Coldcard Entropy Bug Exploited for $100M in BTC Heist
A security flaw in one of the longest-running hardware wallets has left Bitcoin holders on edge. The Coldcard entropy bug, discovered July 31, has been exploited to steal over $100 million in BTC through coordinated attacks.
The issue lies in the wallet's ability to generate random numbers, which is critical for securing private keys. Researchers have found that certain firmware versions of the device can produce weak entropy when generating seeds on-device, making it possible for attackers to reproduce and exploit them.
Wallet manufacturers are emphasizing the importance of secure entropy generation, with some taking different approaches to achieve this. For example, Ledger relies on dedicated security hardware, while Trezor combines randomness generated inside the device with that supplied by the host computer.
The incident has sparked debate over how users can be certain that their wallet's randomness is actually working. Some argue that independent certification provides the strongest assurance, while others emphasize the importance of open-source development and welcoming external researchers.