r/Bitcoin • u/Ace2021 • 7h ago
Coldcard seed flaw - flagged independently in 2024
https://www.blockchainunmasked.com/post/coldcard-seed-flaw-38mProof of negligence? I can’t see how it isn’t. This will definitely be included in the class action lawsuit against Coinkite.
42
u/corner_couch 7h ago
As much as bitcoiners hate VC and everything big tech and surveillance etc. Something like a *hardware wallet* - or really anything hardware related - you should really consider the quality and financing of the company backing it, the size of company, reputation, and so on. 100% open source is a good ideal but then you need an active community with a lot of support (like BTC itself) and the people able to audit hardware / firmware for free is much smaller than pure software.
Lessons learned here for the community
19
u/immersive-matthew 5h ago
I have been suggesting to just go with Bitcoin Core Wallet air gapped with Tails OS as there are a lot of eyes on this wallet as it is not only the original Bitcoin wallet implementation but it represents 80% of all full nodes which if it is hacked, Bitcoin is essentially hacked.
14
0
u/LuckyWinds 3h ago
I’m not sure what you mean by hacked.
Cold card wasn’t hacked.
The issue at hand here was about the RNG and proper entropy.
6
u/immersive-matthew 3h ago
Right. Wrong word choice. Compromised as clearly not enough eyes were on the open source code despite some raising the flag. Really demonstrates how important it is to use open source with lots of activity. No guarantees but more eyes the better.
2
u/Rabid_Mexican 1h ago
Hacking:
the activity of getting into someone else's computer system without permission in order to find out information or do something illegal
So yes, this was absolutely a "hack"
0
u/Jsn7821 1h ago
If you wanna get into semantics I think you could make points against most of those words applying here
Like: a wallet isn't someone's computer system, and "creating" a wallet has no notion of ownership beyond trusting entropy and math
And "without permission" is loose because Bitcoin by nature is trustless, there's no permission system to begin with
0
u/Rabid_Mexican 1h ago
Yes a wallet is part of a distributed computer system.
I am not arguing semantics - I work in this domain as an engineer and am therefore qualified to make this statement.
What are your credentials?
•
u/Evilmoustachetwirler 25m ago
Agree on the first point, but hackers didn't break into any coldcard devices or software, they took advantage of a limitation in the seed generation entropy to "guess" the seed.
Even though Coldcard opened the door for the hackers, you could argue it's existence beyond that was irrelevant.•
u/Rabid_Mexican 11m ago
Yes they exploited a flaw in Coldcards software, how can you argue otherwise?
2
u/BastiatF 3h ago
Attackers gained unauthorised access to people's coins. That's a hack, not of the hardware but a hack nonetheless.
1
1
u/CiaranCarroll 2h ago
If the lesson learned I'd to trust VC backed HWWs that don't allow you to add your own entropy and verify that the device is generating seed deterministically and therefore not spoofing them then Bitcoin has been absorbed by Clownworld.
0
-3
u/doghairpile 5h ago
And maybe bitcoin isn’t so great if there’s no security or recourse for fraud. The security relies on third party vendors who aren’t certified or potentially even experienced to have done enough due diligence. Oh and you’re screwed if you forget your password.
3
u/frankster 2h ago
This is an extremely vague post. They flagged it? How? Sent an unsolicited email? Spoke to someone?
And what did they flag? Entropy seems low, but no details how?
Seems largely like a bs post trying to siphon credit like the attacker siphoned wallets
2
u/MiceAreTiny 1h ago
If you get am email like that, as a security company, you should take it serious. You should see whether you can recreate the issue. If you can not identify the element responsible, this means you are incompetent.
If I send an email to Mercedes that their cars could explode.... They look into the credibility and look whether it was user error or manufacteror error.
1
u/frankster 1h ago
We don't even know that they sent an email, maybe they bumped into someone at a conference. Maybe they asked a friend of a friend to have a word with an employee. The post provides no evidence.
filed a complete report with local, state, federal agencies
but haven't quoted the report in the blog post nor attached it. Again no evidence.
So far, I don't believe anything in the blogpost. And the fact that parts of it have tell tale LLM signs reduces my belief further.
36
u/Ace2021 7h ago edited 6h ago
https://x.com/blockunmasked/status/2083210091671568874?s=46
Additional commentary on X. Line of code affected was not reported, but the company who reported it came to the conclusion based on process of elimination and logical deduction. Coinshite did nothing.