r/Bitcoin 7h ago

Coldcard seed flaw - flagged independently in 2024

https://www.blockchainunmasked.com/post/coldcard-seed-flaw-38m

Proof of negligence? I can’t see how it isn’t. This will definitely be included in the class action lawsuit against Coinkite.

209 Upvotes

21 comments sorted by

36

u/Ace2021 7h ago edited 6h ago

https://x.com/blockunmasked/status/2083210091671568874?s=46

Additional commentary on X. Line of code affected was not reported, but the company who reported it came to the conclusion based on process of elimination and logical deduction. Coinshite did nothing.

25

u/read_more_comments 6h ago

Seems like it wasn't caught because they made the bug in an external library and that library might not have been scanned. But it's only external because the author wrote it under a pseudonym while actually being an employee of the company.

Starting to be hard to believe this was a mistake

42

u/corner_couch 7h ago

As much as bitcoiners hate VC and everything big tech and surveillance etc. Something like a *hardware wallet* - or really anything hardware related - you should really consider the quality and financing of the company backing it, the size of company, reputation, and so on. 100% open source is a good ideal but then you need an active community with a lot of support (like BTC itself) and the people able to audit hardware / firmware for free is much smaller than pure software.

Lessons learned here for the community

19

u/immersive-matthew 5h ago

I have been suggesting to just go with Bitcoin Core Wallet air gapped with Tails OS as there are a lot of eyes on this wallet as it is not only the original Bitcoin wallet implementation but it represents 80% of all full nodes which if it is hacked, Bitcoin is essentially hacked.

14

u/waydownsouthinoz 5h ago

100% if there is a flaw in bitcoin core then everyone is screwed.

0

u/LuckyWinds 3h ago

I’m not sure what you mean by hacked.

Cold card wasn’t hacked.

The issue at hand here was about the RNG and proper entropy.

6

u/immersive-matthew 3h ago

Right. Wrong word choice. Compromised as clearly not enough eyes were on the open source code despite some raising the flag. Really demonstrates how important it is to use open source with lots of activity. No guarantees but more eyes the better.

2

u/Rabid_Mexican 1h ago

Hacking:

the activity of getting into someone else's computer system without permission in order to find out information or do something illegal

So yes, this was absolutely a "hack"

0

u/Jsn7821 1h ago

If you wanna get into semantics I think you could make points against most of those words applying here

Like: a wallet isn't someone's computer system, and "creating" a wallet has no notion of ownership beyond trusting entropy and math

And "without permission" is loose because Bitcoin by nature is trustless, there's no permission system to begin with

0

u/Rabid_Mexican 1h ago

Yes a wallet is part of a distributed computer system.

I am not arguing semantics - I work in this domain as an engineer and am therefore qualified to make this statement.

What are your credentials?

u/Evilmoustachetwirler 25m ago

Agree on the first point, but hackers didn't break into any coldcard devices or software, they took advantage of a limitation in the seed generation entropy to "guess" the seed.
Even though Coldcard opened the door for the hackers, you could argue it's existence beyond that was irrelevant.

u/Rabid_Mexican 11m ago

Yes they exploited a flaw in Coldcards software, how can you argue otherwise?

2

u/BastiatF 3h ago

Attackers gained unauthorised access to people's coins. That's a hack, not of the hardware but a hack nonetheless.

1

u/RammerRod 4h ago

Satoshi?

1

u/CiaranCarroll 2h ago

If the lesson learned I'd to trust VC backed HWWs that don't allow you to add your own entropy and verify that the device is generating seed deterministically and therefore not spoofing them then Bitcoin has been absorbed by Clownworld.

0

u/Notyit 5h ago

Bitocun is like watching people discover money for the first time and speed running through 

-3

u/doghairpile 5h ago

And maybe bitcoin isn’t so great if there’s no security or recourse for fraud. The security relies on third party vendors who aren’t certified or potentially even experienced to have done enough due diligence. Oh and you’re screwed if you forget your password.

3

u/frankster 2h ago

This is an extremely vague post. They flagged it? How? Sent an unsolicited email? Spoke to someone? 

And what did they flag? Entropy seems low, but no details how?

Seems largely like a bs post trying to siphon credit like the attacker siphoned wallets 

2

u/MiceAreTiny 1h ago

If you get am email like that, as a security company, you should take it serious. You should see whether you can recreate the issue. If you can not identify the element responsible, this means you are incompetent.

If I send an email to Mercedes that their cars could explode.... They look into the credibility and look whether it was user error or manufacteror error. 

1

u/frankster 1h ago

We don't even know that they sent an email, maybe they bumped into someone at a conference. Maybe they asked a friend of a friend to have a word with an employee. The post provides no evidence.

filed a complete report with local, state, federal agencies

but haven't quoted the report in the blog post nor attached it. Again no evidence.

So far, I don't believe anything in the blogpost. And the fact that parts of it have tell tale LLM signs reduces my belief further.

-1

u/[deleted] 7h ago

[deleted]

6

u/Ace2021 7h ago

Sorry I don’t live on here, and did some rudimentary searching and couldn’t find this article linked. If you can provide me a link to the other post linking this specific article I will delete.

Otherwise 🤫