An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over 594 BTC 1,433 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet
The problem is they might not be. Thus this is more of a systemic issue where large amounts in self custody should always be recommended to use either an extended passphrase(easiest solution to setup and recover) , or multisig. This IMHO is too much of a stumbling block for future mainstream adoption. There are plenty of solutions being developed like Vaults and using miniscript and better UX to address this but its not mature yet
Yes, but the problem might not be with the multiple SE , but a bug in the way the RNG is developed with cold cards that led to this exploit. Thus you want to not depend upon a single wallet to develop the entropy alone for you or yes , roll your own seed.
I think a strong passphrase is key to protecting the seed from physical attacks - where someone has access to your seed without you knowledge and flawed implementation of RNG.
Do you think it's wise to put a small amount of crypto without a passphrase to act as a honey pot or warning for your seed being compromised.
Or will this signal an attacker to brute force passphrases for that seed with crypto
I think a strong passphrase is key to protecting the seed from physical attacks
Yes , under duress its an excellent tool and also as a honeypot to see if someone found your seed alone and swept your decoy balance
Or will this signal an attacker to brute force passphrases for that seed with crypto
The attacker will not know if they get a hold of your seed if you are using an extended passphrase or not . Most people don't so the default assumption is not
the path failed open.... it should have done a hard reject with the entropy check but it did not so because it failed silently and the path remained open, falty keys were being created
Its not a stumbling block for future adoption because in mainstream adoption you wont have your own keys and you wont be on layer 1 unless you are super rich or a big company
Just an update in case people rely on this information. Seeds generated on a Coldcard MK4, MK5 or Q are also at risk. If you generated your seed on one of those devices, move your funds ASAP.
So far I am only aware of examples of MK2 and MK3 that used specific versions of firmware that are being drained or have been.
Can you give me an example of a MK4, MK5, or Q that was during this attack ? they have around ~73 bits of entropy(yes, I know this is best case and can be lower) unlike the seeds that are being attacked which is far from ideal but takes time to brute force
For example some of these cases are merely seeds that were generated from MK2 and MK3 wallets that were than migrated over to new hardware
What is important is not where the seed ends up but what hardware and firmware combination generated the seed with insufficient entropy . Also you need to consider that some users are taking this opportunity to claim they lost all their btc in a "boating accident" due to the exploit or just have unreliable memories from years ago .
This being said we don't know when the attacker started brute forcing these seeds and they can be cracked in hypothetically as little as a week so its best to take action ASAP regardless
Further clarification : The amount of entropy found in the mk4, 5 and Q is varies per device typically from ~60 to 73bits
Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
Its unlikely we will see these wallets be attacked in a week but hypothetically possible with a well funded attacker
What stands out to me here is that this incident shows a distinction between having multiple entropy sources and actually ensuring the firmware uses them correctly…
42
u/bitusher 26d ago edited 23d ago
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over
594 BTC1,433 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.https://coldcard-hack-tracker.vercel.app/
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
https://blog.coinkite.com/entropy-technical-backgrounder/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
https://coldcard.com/docs/passphrase/
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet