Coldcard Bug Exposes Flaw in Hardware Wallet Security
A recent series of thefts has led Bitcoin holders to re-evaluate their trust in hardware wallets, specifically those from Coldcard. The issue stems from a bug introduced in firmware version 4.0.1, released in March 2021, which used MicroPython's Yasmarang PRNG instead of the STM32 hardware RNG.
Analysts had previously characterized this as a pre-programmed fallback, but Coinkite disputes this characterization. The use of the Yasmarang PRNG resulted in seeds with only 40-70 bits of entropy, far short of the required 128 bits for a secure 12-word seed phrase.
Attackers have successfully brute-forced private keys since July 30, stealing over $100 million worth of BTC. Those who added additional dice entropy or used a BIP-39 passphrase and non-standard path were less likely to be affected.