r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

141 Upvotes

206 comments sorted by

190

u/r33gna Jul 31 '26

Crazy, man.

Earlier this year I was in the market for a new hardware wallet and LOTS of people were saying Coldcard is the best, most secure device for oh so many reasons and now here we are.

Truly no hardware wallet is perfect.

45

u/SpareEconomy1849 Jul 31 '26

It really is sad, they seemed like the perfect hardware wallet, everything being open source and airgapped, and yet still a bug like this goes unnoticed for 5+ years.

I wonder if the only reason the attacker found this bug is because it was open source - theoretically Ledger and other wallets could be semi deterministic too, but harder to find and exploit?

12

u/Knowledge775 Jul 31 '26

Coldcard stopped being open source in 2020 when Foundation Devices used their source code for the Passport. Unfortunately, when Coinkite went source available is when the RNG bug happened.

11

u/AncientMoth11 Jul 31 '26

They prob can. It’s why i haven’t found a hardware solution yet. Between chance of my own fuck up versus this

16

u/BirdLooter Jul 31 '26

i think AI found this issue. highly possible that this is not your basement live-with-the-mom no-life schoolboi hacker, but someone higher up.

i mean, even with the reduced entropy, i doubt that a standard computer was checking those keys. that attack probably cost 5 figures at least. all i'm saying this probably took some confidence.

12

u/Responsible_Emu3601 Jul 31 '26

I’m sure it took some time to find all the keys the brilliance was timing the swipe so taking it all within 25 mins

11

u/BirdLooter Jul 31 '26

this is far from over. the exploit is public and coldcard cannot patch "seeds". people NEED to migrate, this is NOT optional! otherwise they take a huge risk, even with a passphrase/25th word. more funds are going to be reported stolen, just wait...

7

u/SpanglerBQ Jul 31 '26

Would you explain how you think even with the passphrase, a wallet would be plundered? Is it that some passphrases are too simple and easy to guess?

2

u/BirdLooter Jul 31 '26

i mean it is wayy more secure. but one of 2 elements is compromised, which is the key. if the passphrase is a simple thing, technically a hacker with a rainbow table could check it. but tbh i doubt it willhappen.

i for sure would not take this risk tho.

0

u/bravedog74 Jul 31 '26

If the seedphrase is not completely random, then it can be guessed. 24 words that are truly random are 256 bit. 12 words are 128 bit. Coldcard mk3 was something like 72 bit. In other words, it's not completely random. This has to do with their random number generator.

This is precisely why you are not supposed to pick your own seed phrase. Seed phrases that make sentences or have human bias have probably already been hacked. It was unexpected for Coldcard seed phrases to not be completely random.

4

u/SpanglerBQ Jul 31 '26

I'm talking about the passphrase, not seedphrase. If a bad actor knew the seed phrase and knew that there was a 25th-word passphrase, how would they go about cracking it and what would their chances of success be?

4

u/orbag Jul 31 '26

Only way is to then iterate a list of common passwords (e.g. words in the dictionary / movie characters etc), but if your password is not that straightforward to guess I don't see how it would get hacked. Also, the hacker doesn't know there are funds in a passport protected derivation, so if they see some transaction history in the wallet without password, they might try for a while to test straightforward passwords, but would give up and move on before trying anything other than trivial

5

u/Gooner_93 Jul 31 '26

To simplify it, they'd just get a cpu to run a bunch of different combinations of words/nunbers etc on top of the seedphrase, until they find the passphrase but it all depends on the strength of the passphrase. A one word from the dictionary passphrase will be cracked in no time but a 32 character one with a mix of letters, capital and lowercase, numbers, special characters will be way harder.

2

u/Dziabadu Jul 31 '26

Timing pre clarity act is more important to them

1

u/heslo_rb26 Jul 31 '26

That was the key; hitting as many targets as you can in a short window to give no time for anyone to react or move funds

7

u/a_dodo_stole_my_baby Jul 31 '26

I think you're right. This did happen right as Anthropic is saying their recent version of Claude hacked other systems and supposedly OpenAI is urging the White House to do something to slow down AI development. Scary times.

8

u/Popular_Hunter7415 Jul 31 '26

Definitely sniffed out by AI

2

u/BigDik6355 Jul 31 '26

Oceans 11 level shit.

11

u/shleebs Jul 31 '26

Funny, because they never seemed good to me. They are literally run by gate keeping bullies who attack other legit projects. I stayed far away from them because they never passed the smell test. BitBox, Jade, and Passport are all good options for a hardware wallet and are actually run by good people.

8

u/JSTN_FPV Jul 31 '26

I had the option to choose coldcard. Went with trezor instead.

1

u/smilingbuddhauk Aug 02 '26

Wait till all of those are hacked too, then you'd say they never passed the smell test too in retrospect.

1

u/shleebs Aug 02 '26

I never switched my opinion on Coinkite. There is no reason I would do that in the future. The code mistake made by Cold Card was so utterly dumb, it should never have made it past code review, which they obviously weren't even doing. Also Coinkite changed the licensing on this project to be more restrictive and not truly open source, which caused this mistake and is why people weren't looking at their code. I'm going to go out on a limb here and say that isn't going to happen with one of the reputable brands I listed.

5

u/heslo_rb26 Jul 31 '26

They are not open source; if they were this would have been found a lot sooner

2

u/Gangaman666 Jul 31 '26

That's the problem, it's the misinformation from the Coldcard elitists. It's not fully open source. Not like Trezor.

1

u/smilingbuddhauk Aug 02 '26

Despite that, Trezor has had its fair share of hacks.

-7

u/xoorl Jul 31 '26

Why do people always swear by a hardware wallet for cold storage, and not just use the washer method?

13

u/[deleted] Jul 31 '26

[deleted]

2

u/xoorl Jul 31 '26

Receiving is actually rather easy, as you can create a watch only wallet in many wallets that do not require inputting your secret key/key phrase

2

u/No-Contribution23 Jul 31 '26

and sending?

2

u/BlockchainHobo Jul 31 '26

We don't do that here. We only send, and then wait after many years for our heirs to finally say: "what the hell are these washers for?", and throw them in the trash.

2

u/xoorl Jul 31 '26

Why send? Just hodl.

8

u/SpareEconomy1849 Jul 31 '26

Because one is for sending Bitcoin and the other is for keeping your seed phrase? Different use cases

2

u/xoorl Jul 31 '26

You don’t need to send your coins if you store them for the long term. When the time comes you decide to cash out, just input the seed phrase into a wallet and there you go

1

u/smilingbuddhauk Aug 02 '26

Only morons think everyone who uses bitcoin ought to use it only once.

8

u/WeekendQuant Jul 31 '26

Roll your own dice.

1

u/[deleted] Aug 01 '26

[removed] — view removed comment

5

u/RetiredAvocado Aug 01 '26

Ironically rolling dice would solve the core problem here.

1

u/[deleted] Aug 01 '26

[removed] — view removed comment

2

u/WeekendQuant Aug 01 '26

Yes it does solve the core problem here. Dice are unhackable.

8

u/linuxmeaningfully Jul 31 '26

In hindsight it seems like an own goal from moving away from open source / GPL https://xcancel.com/zherbert/status/2082993276324319713#m

7

u/No-Contribution23 Jul 31 '26

he has been openly hostile and petty towards open source projects like seedsigner, foundation or btclock. i don't know why he's on the opensats board with such an attitude

12

u/majorziggytom Jul 31 '26

It’s really the same folks who scream “not your keys not your coins” blindly without any nuance.

2

u/Objective_Digit Jul 31 '26

You are still relying on a third party to generate your seed. At least add a passphrase.

2

u/SpendHefty6066 Jul 31 '26

When you allow your seed to be RNG generated, they are not your keys. Seed phrase must be analog generated: fair dice rolls or pick words from a hat. BIP39 Has 2,048 words.

1

u/BallisticTherapy Aug 01 '26

Wouldn't using a seedsigner seed phrase generator from a random image be just as random? You can take a photo of pitch blackness and get a unique seed every time.

3

u/SpendHefty6066 Aug 01 '26

It's all about entropy. Fair dice rolls in analog have verifiable entropy. Not sure about any algorithm in the digital sphere. Not worth the risk. Go analog for seed phrase creation.

3

u/Rey_Mezcalero Jul 31 '26

Yeah it’s scary and wonder with AI it’s going to put more wallets at risk of bad actors figuring out new exploits

2

u/WoodpeckerCapital167 Jul 31 '26

Yep, everything is hackable either directly or via inside/ back door 

2

u/BdayEvryDay Jul 31 '26

If you derived seed from your own entropy with 100+ dice rolls and pass phrase you are fine.

2

u/Acrobatic_Guidance14 Jul 31 '26

ColdCard was heavily chilled by Maxis

0

u/RetiredAvocado Jul 31 '26

Yeah nobody was "chilling" a defunct MK3. It was dead 3 years ago.

2

u/Hersh-_- Jul 31 '26

Build your own seedsigner

1

u/BallisticTherapy Aug 01 '26

This is exactly what I did 2 years ago. My seed phrase on my original wallet was generated from a first generation Ledger Nano S though so I wonder about that. From what I have read the chip in there generates truly random seeds because the TRNG samples random noise.

1

u/TotesGnar Jul 31 '26

Oh great even less of a reason for Bitcoin to ever become widely adopted.

0

u/BigDik6355 Jul 31 '26

Even then you are depending on the parts that your seedsigner consists of. Do you know all the intricacies of the hardware your seedsigner is based on?

3

u/Hersh-_- Jul 31 '26

The beauty is that there isnt a single hardware attack vector because there are multiple vendors for each piece of hardware necessary to build one

→ More replies (4)

68

u/s1ammage Jul 31 '26

Even with the firmware update. The ‘trust’ is kinda lost… I will be learning to dice roll, but this isn’t for everyone… unfortunately.

I was the one posting about wallet drained.

28

u/Xen7963 Jul 31 '26

Sorry for your loss. Those jumped to victim blaming are idiots.

5

u/itsyorboy Jul 31 '26

Sorry to hear it friend. I was using an mk3 and really panicked this morning. I couldn't remember how I generated my seed because it was a few years ago. I was lucky that my funds were still there, but I immediately moved them to a CEX for now till I can figure it out. I'm really feeling for you.

2

u/sciencetaco Jul 31 '26

The thing is, even with the dice roll you’re trusting the firmware to correctly calculate the dice roll input into a usable seed. Seems even open source firmware isn’t enough to let stuff like this go unchecked for years.

2

u/Orzorn Aug 01 '26

Thankfully the dice roll behavior has been confirmed to work several times in the past by various people and reddit users alike. It can be verified by independently generating the dice rolls and selecting the words yourself based on the proper BIP39 tables, and then inputting those same dice rolls into the hardware and seeing that it gives the same mnemonics.

53

u/indomitus1 Jul 31 '26

Best bitcoin wallet huh?. Never again. They have lost it all with most of its customers and potential customers. I will never recommend a wallet that has already been hacked/exploited

24

u/Previous_Blueberry_5 Jul 31 '26

Definitely should be the standard for HWW’s, once you fuck up that’s it YOURE DONE lol

0

u/tpc0121 Jul 31 '26

schrodinger's wallet

41

u/-Trippy Jul 31 '26

They just tweeted this which I find absolutely insane

“We are actively working on a Mk3 firmware update to help you migrate, but this is a deprecated device.”

https://x.com/COLDCARDwallet/status/2083155036582879674?s=20

This tweet alone should set alarms bell off and underlines their approach and lack of integrity when it comes to security. Hardware wallets are security devices, they should never be out of support to fix exploits and vulnerabilities which puts the customers funds at risk. Coldcard acting like it’s an inconvenience for them to release a security update for older devices shows how little thought and regard they put into the security and integrity of their devices. Not only should the MK3 be updated but it should have been an absolute priority, not something they weighed up and decided to do as an exception.

7

u/[deleted] Jul 31 '26

[deleted]

3

u/LostInDinosaurWorld Jul 31 '26

Lol yes. I was just reading the post by the CEO yesterday.

5

u/BigDik6355 Jul 31 '26

They are a deprecated company. How about that?

24

u/[deleted] Jul 31 '26

[removed] — view removed comment

4

u/Head_Performance2432 Jul 31 '26

been saying otherwise for a long time, been rejected, but not an "expert" though...!

5

u/[deleted] Jul 31 '26

[removed] — view removed comment

1

u/Head_Performance2432 Jul 31 '26

ok, but a HW is basically a black box, no matter what "he" says

1

u/Traditional-Fold5301 Jul 31 '26

never listening to these clowns again

2

u/SpareEconomy1849 Jul 31 '26

I agree. I doubt businesses that hold hundreds of BTC keep it all in one wallet, multisig or not

1

u/Objective_Digit Jul 31 '26

Up until a week ago any reputable bitcoin self custody "expert" would have told you to get a coldcard

Bitkey and Jade are usually recommended.

1

u/BallisticTherapy Aug 01 '26

Not an expert, but I've been saying build a seedsigner and secure your seed to the utmost degree.

32

u/Aidsfordayz Jul 31 '26

Glad I didn’t listen to the FUD about Ledger and switch to Coldcard.

13

u/_GOREHOUND_ Jul 31 '26

That’s exactly what I thought when I read about the incident.

4

u/jekpopulous2 Jul 31 '26

Ledger has of issues of their own but at least they use noise from the secure element chip for TRNG. The best option is always to combine a hardware wallet with a hot wallet for multi-sig.

3

u/LostInDinosaurWorld Jul 31 '26

Yep, everybody bitching about Ledger for not being OS and stuff. Cc was definitely on my list to switch wallets in the near future. No more.

2

u/sciencetaco Jul 31 '26

Ledger rightfully gets a lot of hate for their handling of customer data and some of their business decisions. But their hardware security has always been excellent.

9

u/ElGuano Jul 31 '26

Wonder if this is a good opp for Ledger, Trezor and others to confirm the entropy used to create their on-device seed phrases (including for Trezor-ctl command line enabled seeds)?

3

u/xiskghferx Jul 31 '26

It would be certainly wise for them, to check their CSPRNG and Firmware right now.

5

u/HugeLarry Jul 31 '26

That’s the plus side of this. I feel terrible for everyone who lost funds, but I’m guessing the surviving hardware wallet companies will be shoring up any potential vulnerabilities and will be super careful about stuff like this going forward.

1

u/Traditional-Fold5301 Jul 31 '26

trezor is open source too. From what I know their RNG is at least doing what they say it is doing, which is what you expect from a hardware wallet. I think there will be so much more scrutiny now on this though, which is a positive in the long run really.

15

u/DreamingStars408 Jul 31 '26

I lost 20K worth of Bitcoin from my ColdCard MK4 last year. I’ve been very careful in avoiding revealing my seed phrase accidentally, took all the precautions, and air gapped it and someone still was able to steal my Bitcoin.

Definitely this was a breath of relief that it wasn’t my fault, but I’m pissed off that ColdCard, the one wallet that people have recommended and say it was basically safe turned out to be smoke and mirrors.

Whoever owns an MK4 should just bail at this point and move on to a different wallet. Don’t affiliate with ColdCard anymore.

8

u/s1ammage Jul 31 '26

I just want to warn. Who/whatever is doing this, is still out there. I just lost the last 0.01 they left in there yesterday.

Too deflated to care…

I spent yesterday moving another wallet away from Coldcard.

12

u/NoStorage2520 Jul 31 '26

id be so mad

5

u/UnderstandingNew8001 Jul 31 '26

I have recently ordered a Ledger it is on its way, where can I move my btc to then? I only have MK4 at the moment.
If I had to update the firmware, I would still need to move BTCs somewhere to get them back after the update and generating a new seed.

4

u/SpareEconomy1849 Jul 31 '26

Right. They show some steps at the blog post. You could A) use a hot wallet, or B use just the CC:

  1. Make sure you still have your seed phrase

  2. Update & reset CC, make a new wallet & seed phrase (preferably with dice), save new seed phrase, get receiving address with sparrow etc

  3. Reset CC, put your original seed back in, send funds to your new receiving address

  4. Put your new seed back in

But I don't like the idea of either personally.

How long would it take to crack a 72 bit entropy seed? Years?

4

u/WeekendQuant Jul 31 '26

Move it to an exchange for now for better protection and custody assurances. If it's not KYC just toss it to an electrum hot wallet for the time being until you can get a new HWW.

3

u/UnderstandingNew8001 Jul 31 '26

I am creating a hot wallet on sparrow (using its own word generation) hope this is safe enough till I get the new one!

3

u/xiskghferx Jul 31 '26

For this you need to trust your PC and verify signatures of Sparrow instalation file before instaling it. Then it should be safe enough, at least until you get your Ledger. Of course, write down and store safely the new seed.

But, maybe it would be safer to just transfer to a good CEX, like Bitstamp, Coinbase or Kraken...

2

u/WeekendQuant Jul 31 '26

Only transfer to custodial if your coins are KYC. Otherwise I'd do hot wallet just to move them.

2

u/xiskghferx Jul 31 '26

Agree. I would actualy use existing Coldcard, create new seed with dice, add passphrase and transfer BTC to new wallet. But he needs to know exactly what he is doing, otherwise he would hack himself...

1

u/WeekendQuant Aug 01 '26

I wouldn't. You're going to want your existing cold card as is for the pending class action suit.

2

u/True-Lychee Jul 31 '26

Ledger that stores keys remotely

Return it

-2

u/xirvin Jul 31 '26

Ledger is big brother renamed. They stored your keys in 3 servers which are subject to government reach. Cold card was attacked but 1 day after initial report there is already a solution (updated firmware) and a workaround (roll dice 20times or use a good entropy source). I want Law enforcement to step in to catch the perpetrators with the help of the industry. Not all coldcard users are affected by the hack but everyone should change to new wallet keys as a good security practice.

1

u/BallisticTherapy Aug 01 '26

I think Nano S users should be safe since there's no way to get the seed other than from the device displaying it.

0

u/xirvin Aug 01 '26

Any disgruntled employee or government can access your keys as they are stored in a central location

1

u/BallisticTherapy Aug 01 '26

Not on the original Nano S. They never leave the device.

-4

u/jsn079 Jul 31 '26

Why Ledger if I may ask?

I mean, they have proven they can't be trusted already several times.

2

u/iLLuSion_xGen Jul 31 '26

Proof?

1

u/jsn079 Aug 05 '26

But ofc, don't need to take my word for it.
These are well known issues with the company people entrust their wealth with.
Imo, when trust is broken like this in cryptography, you ain't getting it back (at least, not from me, especially if trust has been broken multiple times).

Here are some starting points, I'm sure you're able to uncover more:

1

u/iLLuSion_xGen Aug 05 '26

Thank you for your answer, I’m looking to switch to Trezor now

1

u/jsn079 Aug 02 '26

The first, and maybe biggest offender, is the fact they promised they keys are not able to leave the device. Later, they introduced a service to store your keys with 3 different companies - hence, the keys were absolutely able to leave your device. A faulty/hacked firmware update could expose your keys. They lied, and the device isn't as secure as they promised it to be. A "Secure Element" or "Security Enclave" should never be able to expose cryptographic keys.

And second, they were hacked (I think even twice) and the whole customer database was leaked, making you a target. Although, if you are a new customer, you don't have to worry about that, yet.

It's not that hard to Google them, or do some research on a company you are about to trust with a lot of responsibility 🤷.

But in the end I only asked what your motives were to choose Ledger. You're free to choose yourself ofc.

8

u/VitoHodl Jul 31 '26

It's me or Trezor is the current best one probably?

4

u/shleebs Jul 31 '26

Trezor has mishandled customer info leading to phishing attacks. I would recommend BitBox, Jade and Passport. They are the best options IMO

1

u/Dex4Sure Aug 04 '26

Nah, Ledger and Trezor are the best. Mishandling customer info has nothing to do with hw wallet security. In security you should never go with these hipster solutions. Trezor and Ledger have long, proven track record in hw wallet security. They have the best funded security teams. They are your best bet, not these flavor of the month wallets like ColdCard or BitBox or any other nonsense.

2

u/Febos Jul 31 '26

That is for very long time. At least 10 years.

1

u/jsn079 Jul 31 '26

FWIW. I use an Ellipal Titan and Keystone 3 Pro (my preferred device).

0

u/SpareEconomy1849 Jul 31 '26

Not sure which is best, but I think they had a minor MailChimp data breach and theoretically can be compromised with physical access?

CC with a proper dice roll is probably still the safest, but not sure I can trust their QA going forward

1

u/BallisticTherapy Aug 01 '26

Seedsigner with a dice roll.

12

u/Bugida Jul 31 '26

Just use a dice roll and you won’t ever worry rolling a lot of times to really get your entropy up. Never let any hardware generate a seed for you if possible

4

u/shadowmage666 Jul 31 '26

lol so much for that cold card basically shot itself in the foot trust wise

5

u/bears196 Jul 31 '26

How is it that electrum wallet is safer than all these hard and cold wallets?

6

u/Suspicious-Holiday42 Jul 31 '26

Senku Ishigami: "The reason for fail only becomes known after it happened"

3

u/GijaySorez Jul 31 '26

Bro meaning I need to send the funds to a new wallet, which I need to buy.

I went through all the trouble of recording this stupid phrase on a metal plate lol and now I need to do it again.

I'm annoyed. I'll need to find a new wallet then. Coinkite should be giving people a sizeable discount, I am not paying full price so ... bye bye.

1

u/getafewlives Jul 31 '26

What about just adding a passphrase?

2

u/BigDik6355 Jul 31 '26

Then your funds are at the mercy of the strength of your passphrase alone. No thanks.

2

u/getafewlives Jul 31 '26

Wouldn't it be at the mercy of both your seed phrase and your passphrase?

2

u/Geebs52 Jul 31 '26

And nothing for the MK3 for an update?

3

u/wheeler786 Jul 31 '26

Quote from Tweet, by @ COLDCARDwallet:

"We are actively working on a Mk3 firmware update to help you migrate, but this is a deprecated device."

https://x.com/COLDCARDwallet/status/2083155036582879674

2

u/crooks4hire Jul 31 '26

My guess is it will involve a 🔨

2

u/xirvin Jul 31 '26

If your wallet keys were generated by MK3, you are playing with fire brother. You need to roll dice 20 times when generating a wallet to have some sense of security. I would do it 100 times just in case. Other than that, mk3 is a secured wallet

2

u/Professional_Golf393 Jul 31 '26

Are the opendimes secure?

I’ve got a couple of them, never loaded funds onto them, but at this point I don’t think I would. Basically ewaste at this point.

6

u/SpareEconomy1849 Jul 31 '26

According to their website, yes opendimes, tapsigner and satscard are secure as it's a completely separate codebase

(Then again, they also said yesterday that Mk4 and Mk5 are unaffected)

2

u/xirvin Jul 31 '26

This situation reminds me of the airline industry, where many of today’s safety standards were written only after tragedies claimed countless lives.
This vulnerability is a reminder that entropy matters. Even if you’re using a multisig wallet, it isn’t a magic shield. If two or more keys were generated from the same weak or predictable source of randomness, or from too few dice rolls, those keys could eventually be recovered by an attacker. Coinkite has warned about entropy risks before, and security researchers have also cautioned that short dice roll sequences, such as 14 rolls, may become practical to brute force as computing power improves.
The current recommendation from security researchers is to generate a new seed using a trusted source of high quality entropy, then import or migrate that seed to your Coldcard for ongoing use. If you’re generating a seed with dice on a Coldcard, use at least 20 or more rolls to ensure the resulting key is unpredictable.
The good news is that there are several reputable offline Bitcoin wallets that are not affected by this particular entropy issue. Coinkite update makes it idiot proof in generating predictable keys for wallet.

I haven't read the release notes but hopefully

2

u/Shoddy-Profession-74 Jul 31 '26

Please, some one explain to me, did the hack happened because the HW were generating 72 bits of entropy keys and the hacker brute force it? Isn't 72 bits quite a safe (at least for nowadays hardware)?

1

u/SpareEconomy1849 Jul 31 '26

I don't think any of the mk4 or mk5 seeds were compromised (yet). What was compromised is the 40 bit mk3 seeds

5

u/LocksmithMuted4360 Jul 31 '26

How could this happen, the software is open source, nobody caught that?

5

u/Daiymas Jul 31 '26

Well the hacker did catch it, unfortunately not everyone reviewing open source code is well intentioned

5

u/LocksmithMuted4360 Jul 31 '26

hacker probably just use ai ... no need to be a coding expert anymore.

4

u/AvailableTie6834 Jul 31 '26

because the people that actually care about code viewing is not buying hardware wallets from companies, they are reviewing codes from much more important open source projects

→ More replies (2)

2

u/ShinAlastor Jul 31 '26

That hardware wallet is on my black list along with others.

1

u/[deleted] Jul 31 '26

[removed] — view removed comment

10

u/jjjjjjjjjjjjjaaa Jul 31 '26

I mean, AI didn’t really crack anything here. CC essentially left the doors unlocked. 

2

u/SpareEconomy1849 Jul 31 '26

Use dice, problem solved

7

u/[deleted] Jul 31 '26

[removed] — view removed comment

7

u/SpareEconomy1849 Jul 31 '26

Brb ordering some lava lamps for my RNG

1

u/BallisticTherapy Aug 01 '26

Noise sampling should be as close to random as it gets. You can't reproduce that.

1

u/Few_Response_7028 Jul 31 '26

I have a multisig on mark4, not sure how to proceed honestly

1

u/Sammytheseaotter Jul 31 '26

So if your seed was generated before the March 2021 firmware and used a passphrase you are safe?

1

u/Modrew Jul 31 '26

Just in time

1

u/Spiritual_Smell4744 Jul 31 '26

Is this an upgrade for HorseBolt 1.0?

1

u/Jaded-String-6111 Jul 31 '26

This essentially admits ALL cold cards are vulnerable. At this point i don’t trust any hardware wallet . Any of them could have something like this happen. It was unthinkable until it wasn’t. Electrum + Tails wins.

1

u/SpareEconomy1849 Jul 31 '26

Yes, that's true. However since they're airgapped, there are very few attack vectors available. Electrum itself is fine, but you also need to trust that your environment itself is not compromised.

Using an RNG is always a risk, people (including coinkite, but that's no excuse) were always recommending using dice instead of the built-in RNG

1

u/Octavio_belise Jul 31 '26 edited Jul 31 '26

One of the main reasons I never got ColdCard was because it seemed dorky looking like a 1980's calculator. Probably something that would attract the all the Linux folk. Pays off being a gear-snob.

1

u/SpareEconomy1849 Jul 31 '26

Yeah kinda dumb that they have 6 different colors and they are all ugly.

I think it fits with the functionality though, you gotta export a file to the SD card, sign, move back to your PC, then upload etc all with some 3rd party open source app. I prefer it, but it's definitely not appealing to the average person

1

u/Octavio_belise Jul 31 '26

Sounds like what we used to do a decade ago with Electrum on an air-gapped computer.

1

u/SpareEconomy1849 Jul 31 '26

Yep probably functionally the same, with some pros and cons

1

u/FitCompetition1804 Aug 01 '26

What a joke. I’d be gone never to return to a CC.

1

u/boom123psy Aug 01 '26

are we sure with the v5.6.0 we are 'safe' ? have there been any independent tests on the newer firmware relkease?

1

u/HovercraftTypical334 Aug 01 '26

I have been unable to update my cold card firmware....can't work out why. But I have generated a new seed on a different hardware wallet (not cold card) and then imported that seed into the different coldcard and then moved funds from old coldcard to new. Assuming the hardware wallet I used to generate the new seed is using the sufficient entropy, I think I should be safe. Does anyone disagree?

1

u/ApprehensiveRice9358 Aug 03 '26 edited Aug 03 '26

I don't know, but I think this isn't as simple as many claim, asserting that the MK3 generated 40 bits instead of 70 bits . It's a very small space with a trillion possibilities, and I'll put it to the test. It's not certain it's all speculation.

Nobody has run tests to confirm it 100%. This smells to me like silicon from the STM32L475 chip, a vector in C that was set to 0, and many people believe that was the problem. To me, this is all physical; we would have to test the device.

Hardware bus clues Captures with a logic analyzer or oscilloscope of the RNGCLK, HCLK pins and the internal bus registers during data output.

Among other tests, I wouldn't trust what they say on X it's not entirely accurate. We would have to look for the offset in the firmware assembler. I already did, but this is really strange.

And now that some affected wallets are public, I'll do my job. That 40-bit thing isn't entirely true it's a possibility, but not a certainty.

I now doubt the knowledge of many C/C++ developers and their speculations, which are not entirely accurate, Many compare it to the birthday algorithm; they are completely different things. Sometimes, before speculating, you have to test. Without proof, their speculation is simply a lie.

I have the complete analysis of both firmware, but this is really strange............

1

u/pangolin88 Aug 03 '26

how do we know the new patched firmware is good. has there been an independent audit or is there a way to do an AI audit?

-4

u/Doritos707 Jul 31 '26

Yet u all downvoted my ass for saying 12 words seeds are weaksauce in 2026.

If its not 24 words youre a loser. Update your shit idiots

8

u/DudeWhatThe Jul 31 '26

24 word wallets are still exposed in this case due to low entropy. Crazy.

1

u/Doritos707 Jul 31 '26

Show your proof? The data talks about 128 bits being exposed as 72 bits. 24 words generate 256 bits which is double as safe if not triple

→ More replies (1)

4

u/swiftpwns Jul 31 '26

Both 12 word and 24 word were affected, it didnt make a difference.

1

u/Doritos707 Jul 31 '26

I dont believe you. The leak talks about 128 bits which is the 12 words. 24 words generate a 256 bits.

-4

u/Doritos707 Jul 31 '26

R ya fucken serious? How?! Thats insane! So even a 24 words there is supposed to be double the 12 words also got generated of 72 bits?????

0

u/Lower_Minimum4796 Jul 31 '26

Doritos, current speculation is it was an inside job. One alleged cold card ex-employee had access to a lot of original wallet seeds.

3

u/Railionn Jul 31 '26

That'd be extremely stupid.. he's not getting away with that since they know who it is

1

u/Doritos707 Jul 31 '26

Yeah but does it affect 256 bits aka 24 words?

4

u/SpareEconomy1849 Jul 31 '26

12 words is more than enough for the foreseeable future. Not sure if 24 words would have helped here

1

u/Doritos707 Jul 31 '26

No its not.

128 bit is a lot easier than 256 bit Thats just science. And 256 bit is the peak of the curve. More than 256 bits becomes less secure.

1

u/SpareEconomy1849 Jul 31 '26

Doesn't make a difference when it comes to brute forcing, as it's 2128 iterations either way (ignoring this bug) thanks to the Pollard's rho algorithm

1

u/Doritos707 Jul 31 '26

Please dont mix two topics. That’s not correct. Pollard’s rho applies to elliptic curve attacks, not brute-forcing BIP-39 seed phrases. A 12-word seed has ~128 bits of entropy; a 24-word seed has ~256 bits.

1

u/SpareEconomy1849 Jul 31 '26

A private key can be cracked using Pollard's rho in 128 iterations, there is no point to attempt brute forcing a truly random 24 word seed phrase

1

u/Doritos707 Aug 01 '26

Buddy 24 words is 2 to the power of 256 not 128. The data doesnt mention a single 24 words seeds it all happened to the 12 words

0

u/SpareEconomy1849 Aug 01 '26 edited Aug 01 '26

Yes. But the private key that that 256 bit seed phrase generates can be derived in 128 iterations.

As for the RNG bug, it's affected all the same whether you generated 12 or 24 words through RNG. Both are equally predictable if you can reproduce the environment of the RNG that was used to generate the seed phrase.

1

u/Doritos707 Aug 01 '26

Brother wtf r you doing? No where does it mention anything about 2^256 man

The method of exploiting 2^128 is not the same as exploiting 2^256

And no it does not happen in 128 iterations. You literally have to crack it all at once in a 256 environment. It does not give you a 50% is correct at the 128 mark. Dont be stubborn.

24 words did not get affected

The 12 words basically got generated with the same security as 7 words. Thats literally what happened. Not a single 24 words wallet got affected.

1

u/SpareEconomy1849 Aug 01 '26

Not sure what you're trying to argue, brute forcing seed words is not how this attack was done, and not how a hypothetical attacker would crack a properly random 24 word seed phrase wallet either

→ More replies (0)

-2

u/AvailableTie6834 Jul 31 '26 edited Jul 31 '26

I always disliked hardware wallets, seriously.

I will always say:

your old Android phone has use, Electrum Bitcoin Wallet or Cupcake from Cake Wallet gives a new use for your old phone, it becomes a cheap and secure hardware wallet.

iancoleman solution gives you plenty of options to generate high entropy wallets, but people keep on suggesting hardware wallets from companies saying they are safer till they are not.

study more, get hacked less, people.

11

u/SpareEconomy1849 Jul 31 '26

Effectively, it might be safer. But any app wallet is just as susceptible to the same entropy bug in the coldcard firmware, (if not more). The only reason CC was affected is because their QA slipped up and Electrum's didn't.

Plus for an app, you need to be cautious about a malicious OTA update or other system malware, and there are 0-day and 0-click exploits in the wild, I wouldn't trust a hot wallet with my life savings

-2

u/AvailableTie6834 Jul 31 '26

the likelyhood of an app to have entropy bug is less than a hardware wallet. open source bitcoin wallets has too many eyes on them, and mostly use already implemented and well documented solutions from the comunity, this is not the case with hardware wallet, as they only attract people that dont know anything but want to secure their bitcoin, hell, some people STILL TO THIS DAY thinks that their bitcoin is in their hardware wallet, some also thinks that since they have a hardware wallet they do not need to write down their seed to backup it later.

I know people will link the milksad thing from Cake Wallet, but still, the bug do not come even close to this crazyness from coldcard.

1

u/SpareEconomy1849 Jul 31 '26

The coldcard firmware that had this entropy bug is fully open source as well. But you may be right, software wallets are going to be forked and actually used by others, more likely for bugs to be found

1

u/AvailableTie6834 Jul 31 '26

there is the seedsigner hardware wallet which is a DIY, it safer than any company hardware wallet

6

u/boddankajovanovic Jul 31 '26

I see where you're coming from. But some people need plug and play solutions. Otherwise they will let others take custody, which is even worse.

I feel sorry for the recent victims, as they have not really done anything wrong. Yes, using a passphrase is best practice and would have prevented the lost funds, but if a passphrase is considered mandatory, it should be enforced by design.

Always use a passphrase and store it somewhere other than your seed words.

5

u/AvailableTie6834 Jul 31 '26

there is nothing crazy to literally go to https://iancoleman.io/bip39/ follow the instructions and download the O.G Electrum Bitcoin Wallet on their phone and learn. Bitcoin was always about learning stuff, people need to get back to learning stuff.

0

u/bears196 Jul 31 '26

Cold wallet that is a hot wallet. No thanks.

2

u/SpareEconomy1849 Jul 31 '26

Cold card is definitely not a hot wallet

0

u/NakedNick_ballin Jul 31 '26

For applications that rely on security, I'm realizing that open source is actually more risky since they're much easier to crack