Coldcard offers deeper security fix after Bitcoin theft

Coldcard offers deeper security fix after Bitcoin theft




Coldcard offers deeper security fix after Bitcoin theft | Without a bank



















Coinkite’s new firmware adds manually entered entropy and more stringent transaction checks to its Coldcard wallets.

Weeks after Coldcard hardware wallets had over $100 million worth of Bitcoin stolen due to a random glitch, Coinkite… Released firmware 5.6.1 For Mk4/Mk5 and 1.5.1Q for Q. This update arose from an AI-assisted security scan that delved into much more than the original bug.

What is the scoop?

  • root cause: A configuration bug introduced in Coldcard’s 2021 firmware quietly downgraded the source of randomness, so seeds intended to carry 128 bits of entropy were sometimes shipped with as few as ~40, which was weak enough for attackers to be able to guess the private keys without needing physical access.
  • What has changed: New seeds must now rely on randomness provided manually by the owner, i.e. rolling a dice, tossing a coin, or an unpredictable series of keystrokes. These inputs are layered on top of the device’s hardware entropy, and a new SHA-256-based generator now supports them. Coldcard also re-scans the contents of the transaction immediately before signing, closing the opportunity for a compromised computer to manipulate subsequent approval.
  • The catch: Seeds produced between 2021 and this July are still considered burnt regardless of the update. Any owners from that period would still have to build new software on the patched firmware and roll over their money if they haven’t done so already.

Without a bank

2768 posts

It’s time to break up with your bank and join the movement for a better world.

Leave a Reply

Your email address will not be published. Required fields are marked *