Coldcard Flaw Sparks Fears of Bitcoin Self-Custody Risks
A recent security flaw in Coldcard's hardware wallet has led to concerns about the safety of Bitcoin self-custody. The vulnerability allowed an attacker to steal $38M worth of BTC from Coinkite's system, which shares part of its design with other providers. However, Ledger and Trezor have distanced themselves from the issue, stating that their own hardware wallets are not affected.
Ledger explained that it uses a 256-bit mathematical complexity system (entropy) to generate seed phrases, making them difficult to crack. In contrast, Coldcard's flaw downgraded its system from 128-bit to a guessable 40-bit system, which can be easily compromised using brute force.
Trezor also assured its users that their funds are safe, citing the fact that they do not share Coldcard's custom firmware and randomness generation code. Despite these assurances, the incident has sparked broader fears about security on hardware wallets and self-custody in general.