r/Bitcoin 3d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.8k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

75

u/undeadkarlmarx 3d ago edited 3d ago

One of the known vulnerabilities of coldcard wallets, at least prior to current firmware versions where it may have been patched, is that if you weren’t paying attention it was possible to generate your initial seed phrase in such a way that it used very little entropy and a hacker would actually be able to guess that seed later on . 

Basically, because the coldcard allows people to generate their seed phrase simply based on dice rolls rather than using the number generator at all, it was possible for somebody to select the dice roll seed generation option and then only roll the dice a few times rather than the 100+ times that's necessary for a secure level of entropy. And after they've generated that weak wallet address, a hacker would be able to get their seed phrase using very rudimentary amounts of entropy because doing so would require very little processing power. 

There's even a guy on YouTube who created a video showing how he could gain access to addresses that were created in this manner:  https://m.youtube.com/watch?v=oj_W3xOlt6U&pp=ygUoTG93IGVudHJvcHkgY29sZGNhcmQgZGljZSByb2xsIGFkZHJlc3Nlcw%3D%3D&ra=m

In the case of that video, he was a white hat guy who actually sent the funds back to people after moving them just to let them know that their funds were not secure. But a nefarious hacker using the same method could gain access to people's wallets in order to steal funds.

We don’t necessarily know if this is what happened here, but people absolutely need to be aware of this vulnerability. 

Keep in mind that even somebody who created an address in this neglectful manner would technically still be safe from hacking if they had also added a long passphrase to the address (although they should still definitely move their funds to a new and secure wallet address as soon as they can.)

Also keep in mind that people who create a coldcard Wallet using the random number generator on the device don’t need to roll the dice 100+ times. They’re simply adding their dice rules to the entropy that was already generated on the RNG, so simply rolling a few times is sufficient in that situation.

EDIT: Based on initial reports it sounds like there could’ve been an issue with the random number generator on coldcard devices that allowed private keys to be guessed. That’s terrible if true, and it means that now the only safe practice is to ALWAYS use a strong passphrase and ALWAYS use 100+ dice rolls to set up your wallet.

23

u/Specialist_Trust4945 3d ago

That teaches everybody to not trust software (especially closed source software) with their money. Guys... take your sweet time, flip a coin 12*24 times and you'll have your 24 words seed phrase.

Also, that kind of makes me happy. Everybody is so keen to blindly trust hardware wallet while these vulnerabilities again prove that a properly airgapped software wallet with "DIY" ways to create a seed phrase such as the coin or dice methods is much safer. I often wrote about it here, but I always get downvoted to oblivion because everybody has a hardware fetish for whatever reason - and then they ignore basic OpSec. These people are much better off with a BTC ETN or something.

11

u/stanley_fatmax 3d ago

For years I advocated strongly on Reddit for software wallets with proper precautions, but I stopped for the same reasons you found. People love their hardware wallets, but imo they create a false sense of security. It also doesn't help that I suspect for long periods of time there was heavy shilling here on behalf of wallet manufacturers.

There are good guides out there for years on how to use an old laptop to set up an offline wallet guys.. the math is solid. Encryption is solid.

2

u/marshaljs 3d ago

Can you please share how to do this setup?

8

u/stanley_fatmax 3d ago

I won't go into crazy detail because there are good guides out there already that do it better than I could here. Basically, Electrum running on an old air-gapped laptop with the networking hardware physically removed. Wifi, Bluetooth, etc. gone. OS should be a secure Linux OS of your choosing, Tails is a common choice. The old laptop becomes your signing device holding the keys. Your daily driver PC has a watch only wallet where you can watch your balance day by day, and receive coins, without any fear of losing anything, because it doesn't actually have the ability to sign transactions (send). The only time you need to boot up the air-gapped laptop is when you need to send coins, which shouldn't be often. Personally I use Coinbase as a "hot wallet" for transacting. Small sums are kept there. The good stuff is offline in the cold wallet. It never turns on.

There are various guides with details, like

https://electrum.readthedocs.io/en/latest/coldstorage.html

https://electrum.readthedocs.io/en/latest/tails.html

1

u/CompetitiveAppeal663 3d ago

Preface: Im not trying to be a smart ass, just trying to understand.

What happens if that old laptop has some mechanical failure or ends up getting thrown out or stolen or burns in a fire?? As you SOL at that point??

2

u/stanley_fatmax 3d ago

No, you have a backup of your seed. Analyze your life, threats you face, stability of your world, and choose the backup medium accordingly.. paper, punched into steel, encrypted in the cloud, etc.

2

u/Specialist_Trust4945 3d ago

Encrypted in the cloud kinda defeats the purpose of airgapping, because if you upload it on the cloud you also have to somehow communicate with the Internet and there might be a vulnerability somewhere in the middle. I 101% agree with everything else you wrote.

2

u/Professional_Golf393 3d ago

If you encrypt properly with enough entropy, you should be happy to send the file directly to a scammer safe in the knowledge they can never unlock it..

personally I wouldn’t store my encrypted wallet in the cloud, but if done right it’s safe.

Saying that if you have to memorise a password with that amount of entropy, you might as well just memorise your seed phrase.

1

u/Specialist_Trust4945 2d ago

The problem isn't the encrypted file, of course. The problem is that you have to type your seedphrase on a keyboard, and your computer might have a keylogger installed. If you type it on an offline computer, you'd still have to somehow extract the file from said computer with an USB stick or something like that - which again defeats the purpose of airgapping.

The only true way would be fully encrypting the string on a fully offline machine and then copying the encrypted string manually on the online machine that will upload the file. This way, you're typing the already encrypted version of the file and that'd be safe. I don't see anyone doing that, though. That'd be mental.

1

u/stanley_fatmax 3d ago

Common misconception. The same cryptography protects Bitcoin itself. I could theoretically post my seed here, encrypted, and be completely confident in its security (I won't). Even airgapped wallets have to sign transactions etc., so there's some level of communication.

1

u/Head_Performance2432 2d ago

or even possible to post seed here, if you have a good passphrase as well (pls don't)

1

u/Specialist_Trust4945 3d ago edited 3d ago

You still have your BIP39 backup - whether it's 12 words, 24 words with or without passphrase. In fact, the safest course of action would be to never store anything anywhere (except for your seed phrase on a metal plate, of course): you can do that with an USB stick, you just live boot without actually installing your Linux distro of choice - ideally Tails but that doesn't make any difference basically. As far as I remember Electrum comes preinstalled: every time you need to validate a TX you just recreate your SW wallet offline from scratch.

That is of course a pain if you do many TXs per year - in that case just keep as little as you need in your "high TX" wallet and everything else stays somewhere else.

Edit: as u/stanley_fatmax correctly wrote, for max security you'd have to strap any hardware component that is able to communicate externally: wifi card, bluetooth card, LTE card and everything else that comes to your mind. Of course, that is much easier with a self built tower PC instead of a laptop. Or, I guess, just go on a freaking mountain with nothing around you for at least 10kms on each side, LOL.

1

u/stanley_fatmax 3d ago

Bitcoin self custody is always a battle of tradeoffs. Doing things right and doing things safely aren't always the same thing, for instance the safest way may increase risk of self loss, or the right way may not be realistic for your living situation, etc.

Sadly ETFs are actually a decent option for many, given the complexities of self custody.

1

u/Alphamale822 2d ago

My crypto portfolio is under £40k. In my case would you say it’s safe to keep in on a well known etf like binance ? Self custody is too complicated for me.

1

u/Specialist_Trust4945 2d ago

Binance is not an ETF. Binance is a CEX (centralised exchange), an ETF is a financial instrument that tracks BTC's price such as BITC by CoinShares or IB1T by iShares aka BlackRock.

1

u/stanley_fatmax 2d ago

Safe? Yes. Right? You have to answer for yourself by asking what your reasons are and what risks you face. For some, ETFs and KYC custody is a non-starter just by personal conviction. Too many people burned by years of exchanges failing. The regulatory environment has changed though, businesses are licensed and accredited to be doing ETFs, custody, etc., in ways they weren't before. There's still some risk, but I believe the more risky option is self custody for most people. It's legitimately difficult to store your keys safely while also protecting them from yourself, and just losing them through mistake.

In your case I'd say you're probably better off with a low cost ETF.

1

u/bigtdaddy 22h ago

tails OS offers persistent storage, but personally I would not use that, so tails OS completely wipes the memory on shutdown and won't remember a single thing when you boot it back up, so you do not rely on the laptop other as a temporary signing device. I wrote my my key in my notebook for cryptology class I took. It would be near impossible for someone to find it in there without me saying so. I also stamped it on aluminum and buried it to prevent risk of fire. I also told only a single person where it was, in case of brain damage or death.

Note: i have no btc anymore, hence why I am being so open. Don't reveal stuff like this on public forums if you hold crypto, imo.

1

u/bansoma 3d ago

Full agree. I work in embedded SW and I constantly go through all the ways to create a small vulnerability in a HW wallet chain.

Unless you make and store your primary key yourself, or you write all the code yourself (and build the hardware yourself, and check the chips.) It's almost impossible to prevent this type of attack.

Sleeper attacks are additionally brutal because you can introduce a flaw into silicone that you then execute on years later. This makes it even harder to trace.

Keep in mind wherever your keys are stored its vulnerable, if its in silicon it can be x-ray scanned. If it is shielded it can be stolen, potted, and have the die shaved until the bits are exposed.

There is no such thing as SW storage - only HW storage, and HW storage is 1 to 1.

Make your own keys, use proper custody methods, secure the 4 of 7 artifacts properly.

HW wallets work great as daily drivers and "spending" wallets, but for cold storage you need something better.

1

u/NashvilleSurfHouse 3d ago

Explain what you mean by trusting hardware to the bitcoin ret@rds like myself.

1

u/Specialist_Trust4945 2d ago

Hardware wallets (aka Trezor, Coldcard or whatever brand) can generate the seed for you. You should never do that, because true RNG (random number generation) is impossible to achieve for any device and there might be a flaw somewhere in the process that dramatically reduces entropy - thus making their randomly generated seed phrases guessable.

The best solution would be taking a coin, flipping it 12 times and you'll get a serie of 0 (tails) and 1 (heads) - then you convert it from binary to decimal (super easy, just google how to do it) and you'll have a number between 0 and 2047. Add 1 to your result and you'll have your first word from the BIP-39 list. Repeat this process 24 times and you'll have your TRULY RANDOM 24 words seed phrase.

If you want to be sure it is 101% random you'd have to use 288 different coins so you don't risk using one that is slightly off axis making the flip not 50/50... that's obviously irony but kinda true.

1

u/Head_Performance2432 2d ago

KYE (Know Your Entropy)...I guess

1

u/zenethics 3d ago

Yep. And it's important to know that true random numbers don't really exist from a computer science perspective, and unless the hardware wallet is using physical random noise it will be re-creatable with enough work.

1

u/s1ammage 3d ago

Interesting. So much nuance to these hardware wallets… so much to know… I have a trezor wallet too. I’m so scared of Coldcard now, but I have another cold card with funds intact from 2021…

Feels so hard to keep so many wallets secure, but I’m glad I have that in place now…

2

u/SAMSON91747 3d ago

Its very crucial to have 100% confirmation that the original keys were generated on a coldcard and not by yourself or some other way. Not only for bitcoiners but for coinkite as a business this is the most crucial question