Bitcoiners Ditch Coldcard in Favor of Dice Throws Amid Low-Entropy Bug
Bitcoin holders are re-evaluating their trust in hardware wallet setups after a catastrophic low-entropy bug was discovered in Coldcard devices.
The bug, linked to publicly observed thefts beginning on July 30, occurs when the device uses MicroPython's Yasmarang PRNG instead of its STM32 'true random number generator' (TRNG) for secure seed phrase generation.
This vulnerability was introduced in firmware version 4.0.1, released in March 2021, and allows attackers to successfully brute-force private keys, stealing over $100 million worth of BTC since then.
A significant number of Coldcard users saved their coins from the exploit by using physical entropy, such as rolling dice, to generate sufficient random numbers for secure seed phrase generation.