Coldcard Flaw Exposes Thousands of Bitcoin to Theft
Users of Coldcard hardware wallets may have been under the impression that their private keys were secure, but recent revelations suggest otherwise. An air-gapped Bitcoin wallet can keep a private key away from the internet for years and still be vulnerable to attack if its seed was created using weak randomness.
The issue stems from a flaw in Coldcard's random-number-generation process, which was discovered earlier this year. The company's firmware contained a setting called MICROPY_HW_ENABLE_RNG that was disabled by default, directing the device to use a deterministic Yasmarang fallback instead of its intended hardware random-number generator.
This meant that users who generated their seeds using affected firmware versions were left with seeds that had much less entropy than they thought. For example, Coinkite estimates that affected Mk2 and Mk3 seeds have around 40 bits of effective search space, while affected Mk4, Mk5, and Q seeds have around 72 bits.
The vulnerability has significant implications for users who stored their Bitcoin in Coldcard wallets using the affected firmware. In some cases, attackers may be able to reproduce candidate seeds elsewhere and identify matching Bitcoin addresses, potentially leading to theft or loss of funds.