Coldcard Exploit Sparks Fears About Hardware Wallet Safety
A recent exploit on Coldcard's hardware wallet led to a $38M loss for its users, sparking concerns about safety in self-custody. Ledger and Trezor, two prominent Bitcoin hardware wallet providers, have clarified that their systems are not affected by the flaw.
Coldcard's firmware had an unfortunate code issue that allowed an attacker to steal funds from the wallet. The problem arose from a downgrade of its True Random Number Generator (TRNG) system from 128-bit to a guessable 40-bit system, making it vulnerable to brute force attacks.
Ledger stated that their hardware wallets use a more secure design with a 256-bit mathematical complexity system (entropy), which makes seed phrases difficult to crack. Trezor also assured its users that they should not be alarmed about the Coldcard incident, as their systems operate differently and do not share the same code.
The incident has caused a broader fear among investors about safety on hardware wallets and self-custody. Coinbase CEO Brian Armstrong suggested that 'air-gapping keys' can help reduce some threats. As a result of the Coldcard exploit, Bitcoin's sentiment dropped to a four-month low, causing its price to drop sharply by nearly 3%.