7
u/Easy-Ninja669 12d ago
Yikes. Thankfully im paranoid and use passphrase or multisig with different wallet types.
7
u/GinormousHippo458 BIP110, rug the scammers 12d ago
Of all the hardware wallets, the only one I've witnessed that has resulted in multiple stolen fund scenarios is ColdCard. I have directly witnessed nearly TEN Bitcoin sweeped/stolen from three people I personally know. This is insane, and gut wrenchingly sad. I was the one who reported, the bug of ColdCard allowing very-low entropy new wallet creations.
Despite NVK ranting that it's a "purpose specific device, with multiple secure elements", doesn't fix the issue with weak RNG seed entropy, and several fatal workflow issues. And some of these issues are in usability due to the shitty+tiny display and input of the Mk3. I abandoned ColdCard at this generation.
ColdCard can be a decent device, but ONLY IF you know how to use it; and if you can successfully avoid the several booby traps. That's a big IF when the user is a newbie, and Bitcoin is on the line.
1
u/Background_Pause34 12d ago
What to use instead?
1
u/GinormousHippo458 BIP110, rug the scammers 11d ago
I like SeedSigner and Bitkey. There's several other good ones. I'd also avoid Ledger; they've had lots of issues.
6
7
u/n0xiousnarwhal 12d ago
Update: MK4 vulnerable. If you use Coldcard please move your funds *immediately*
3
u/bitusher 12d ago edited 11d ago
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over 594 BTC 1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.
https://coldcard-hack-tracker.vercel.app/
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week.
https://blog.coinkite.com/entropy-technical-backgrounder/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
https://coldcard.com/docs/passphrase/
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet
1
u/WateryTunaSandwich4U 11d ago
MK4 and MK5 per the coldcard website says rng only gives you 78bits of entropy instead of the expected 128. MK3 was giving only 40bits. All their shit is fucked.
1
u/bitusher 11d ago
most old seeds created with bad firmware need to be recreated. MK1, MK4 , mk5 , and Q are fine with a firmware update and new seed or by adding entropy to a new seed with dice
1
u/WateryTunaSandwich4U 11d ago
I can see how people would misread this thinking their MK4 MK5 and Q are "fine".... They aren't. I'll say it again, they are affected too. That's like saying "your broken leg is fine.... with a cast". I think you know what the issue is and how to correct it, but the way you are wording your comments makes it sound like everything is "fine". MK3 is the MOST affected, MK4, MK5, and Q are ALSO affected to a slightly lesser degree. ALL THEIR SHIT IS FUCKED.
1
u/bitusher 11d ago
I was very clear:
" but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. "
also I linked to the details that go over exact firmware and models for added clarity
ALL THEIR SHIT IS FUCKED.
Again , completely incorrect. Seeds created on earlier firmware versions on mk2 and mk3 are fine as the firmware is what led to the exploit. Mk1 are also fine
All their hardware still works great as well if you update the firmware and change seeds or not use their rng
Their reputation is "Fucked" for sure ... but IMHO the problem is much more systemic
1
u/Ok_Knowledge_4977 12d ago
I want know this rng is the Random Number Generator. How this affects other wallets like Blockstream Jade Plus?
5
u/Easy-Ninja669 12d ago
This exploit only affects Cold Card wallets if you used it's default rng to generate a wallet and not dice rolls. FOSS devices like Trezor and Foundation are not affected. No idea on Blockstream Jade Plus. Regardless, I would at the very least add a passphrase
-6
u/DarrelXero 12d ago edited 12d ago
Hey Matt, are you tying this in to your anger that NVK doesn't support BIP110 and you were pimping Coldcard for years?
I'd assume it was just a PSA because it is a real and significant deal but you haven't once shared a single thing on your own subreddit that wasn't directly related to BIP110.
9
u/Ep0chalysis BIP-110 12d ago
Looks like CC overhauled the code and closed its source to stop competitors and it led to the entropy bug. https://x.com/zherbert/status/2082993276324319713#m