Coldcard Entropy Flaw Exposed as $100M+ Stolen from Hardware Wallets
A critical vulnerability in the Coldcard hardware wallet has been exploited to steal over $100 million worth of Bitcoin. The flaw, which affects multiple devices, relates to entropy generation - a key component of secure seed phrase creation.
Researchers at Galaxy Digital discovered that attackers were able to access and exploit this weakness, resulting in the theft of 1,596 BTC. Coinkite, the company behind Coldcard, has since released firmware fixes and advised affected users to migrate their funds.
The incident raises questions about the security of hardware wallets and highlights the importance of robust entropy generation. According to Michael Tanguma, head of product at Onramp Bitcoin, 'the whole model rests on trust that the vendor got it right.' However, he notes that 'almost no individual can audit the hardware, firmware, and entropy generation underneath their device.'
Jameson Lopp, a Bitcoin security expert, points out that weak random number generation is not unprecedented. He notes that RNG vulnerabilities have previously affected various cryptocurrency wallets and libraries.
Ledger, Trezor, and Foundation are among the hardware wallet manufacturers who take different approaches to achieving secure entropy generation. Ledger's philosophy centers on dedicated security hardware, while Trezor combines randomness generated inside the device with randomness supplied by the host computer.