Seed Generation Flaw Drains Thousands of Bitcoin Wallets
A hardware wallet's most critical job takes about a second during setup. It generates random numbers and uses them to create your recovery phrase, which in turn produces all addresses and signatures.
Jonathan Goodman discovered this on July 29th when his Bitcoin was suddenly drained. He had followed proper procedures, keeping his device isolated from the internet. The issue wasn't with his wallet or internet connection but rather a flaw in the Coldcard firmware released in March 2021.
The problem occurred during seed generation, which should produce 128-bit entropy. However, the faulty code compiled cleanly and used a software generator seeded from the chip's serial number and timer state, resulting in only 40 bits of entropy. This made it possible for an attacker to guess the seed and access user wallets.
The attack didn't involve hacking or exploiting vulnerabilities but rather reconstructing the flawed generator and deriving addresses based on the compromised seeds. Coinkite shipped a fix within days after being alerted, acknowledging responsibility and emphasizing that updating the device wouldn't repair compromised seeds.