Coldcard Entropy Vulnerability Traced to 2021 Firmware Rewrite
Foundation Devices CEO Zach Herbert has shed light on the origin of the Coldcard entropy vulnerability. According to Herbert, the issue appears to have been introduced during a major firmware rewrite in March 2021.
The rewrite replaced the wallet's remaining GPL code with a new cryptographic library and aimed for technical improvements, including the adoption of Bitcoin Core's libsecp256k1 and faster cryptographic implementations.
Herbert emphasized that there is no evidence the vulnerability was caused solely by licensing factors, but it was introduced in the same commit that removed the remaining GPL code dependency, involving 120 files.