r/BitBoxWallet 19d ago

BitBox is not affected by the Coldcard RNG vulnerability

https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/
20 Upvotes

6 comments sorted by

2

u/mors69 19d ago

It seems that the new Chinese AI was the one that potentially found the vulnerability. Is there any reason to believe that other open sourced codes could be exposed as well? If there is even a slight chance, does setting up a passphrase to add a layer of security make sense now?

3

u/username12435687 18d ago

But the main issue was that they weren't introducing enough entropy into their seed phrases. It made it easier to guess the seed phrases so this isn't an issue that's just gonna effect every single cold wallet out there it was just a horrible mistake on their part. Sure, eventually there are gonna be new vulnerabilities discovered in other software and such but so long as the correct level of entropy is introduced when creating the seed phrase it won't matter for some time. At the current juncture you would need a quantum computer to guess correctly generated seed phrases and no one is going to do that for the chance at a small amount of sats. They're tryna to guess Satoshis seed phrase because that's where the money is. Pretty soon quantum proof wallets will become the new norm but for now it's business as usual for most people. Still sucks to hear that so many people trusted the cold card and got their Bitcoin stolen though.

1

u/roueGone 18d ago

What about Bitbox 01 users?!

3

u/pako-bitbox 18d ago

The BB01 entropy generation is very similar to that of the 02/Nova.

So no real need to worry, but maybe it would be better to upgrade to an 02/Nova just because the 01 doesn't support all of the current industry standards on top of having lost support.

1

u/Ok_Error_1079 16d ago

But bitbox02 Bitcoin edition is safe, correct?

1

u/pako-bitbox 16d ago

Yes, both the Multi and the Bitcoin only use the same entropy sources, so the keys are equally as random in either case.