Hardware Wallets Fall Short: Cold Storage Risks Revealed
Cold storage for Bitcoin and other cryptocurrencies is often seen as a secure option, but recent incidents involving hardware wallets like Coldcard, SafePal, and Trezor have shown that even these devices are not completely risk-free.
The main issue lies in firmware bugs, personal data leaks, and phishing attacks that can lead to losses or put users at risk. One notable example is the Coldcard incident, where 1,082.65 BTC (valued over $70 million at the time) were lost due to a vulnerability in seed phrase generation.
The problem occurred because Coldcard's firmware used a software approach for generating entropy, which included data such as time values, instead of a hardware generator. This reduced the entropy from 128 bits to 72 or even 40 bits on some devices, making it more predictable and vulnerable to brute-force attacks.
Coinkite released a fixed firmware, but the incident highlights the importance of keeping firmware up-to-date and securely creating seed phrases. Other hardware wallet manufacturers like Trezor and Ledger have also weighed in on the issue, emphasizing the need for secure key generation and warning about the risks associated with importing or restoring seed phrases from potentially vulnerable sources.