Register and share your invite link to earn from video plays and referrals.

TFTC
@TFTC21
Truth for the Commoner. Bitcoin, freedom, and truth in the digital age. Daily newsletter + podcast. Subscribe.
Joined October 2017
2.4K Following    116.1K Followers
COLDCARD Security Update: Coinkite Explains the Entropy Bug Coinkite has published a detailed technical breakdown of the COLDCARD seed generation vulnerability disclosed yesterday. During a 2021 migration to Bitcoin Core's libsecp256k1 library, seed generation accidentally started pulling from MicroPython's software random number generator instead of COLDCARD's dedicated hardware RNG. The bug slipped through because both functions shared the same name, allowing the wrong one to be silently selected during the build process without triggering an error. The Mk3 is the most affected device. Seeds generated on firmware 4.0.1 and later have an estimated effective search space of roughly 40 bits, far below the intended 128-bit security target, and those users should migrate immediately. The Mk4, Q, and Mk5 models mixed in additional entropy from their SE1 and SE2 secure elements, bringing the effective search space to approximately 72 bits, better but still well below the 128-bit target. Users need to update their firmware (Mk3 to 4.2.0, Mk4/Mk5 to 5.6.0+, Q to 1.5.0Q+), generate a completely new seed, and migrate their funds to the new wallet. Updating firmware alone does not fix a seed that was already generated by the affected versions. Even users who added dice rolls or a BIP-39 passphrase during original seed creation should strongly consider migrating unless they are certain they used at least 100 fair, independent rolls. Coinkite acknowledged that AI likely helped the attacker discover the bug, noting they had recently used AI to review their own code and it missed the issue entirely. Full technical backgrounder:
Show more
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. ( current evaluating Mk3 firmware release )
Show more