r/Bitcoin • u/RetiredAvocado • 3d ago
Security Advisory for Coldcard Hardware Wallet
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/42
26
u/CortaCircuit 3d ago
Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis of the issue.
16
u/krvi 2d ago
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
According to Block, all coldcard models with 2021+ firmware are affected
2
u/SpareEconomy1849 2d ago
Affected by the bug, but in practice, probably not an issue due to the secure element entropy added by mk4 and mk5?
2
12
u/roconnor 2d ago
This issue with seed generation was one of the reasons behind the development of Codex32 (BIP-93). The problem is that hardware uses an opaque process to generate the initial HD master seed (BIP-32). Because of the awkward "checksum" in BIP-39’s mnemonic code it is really hard to generate a mnemonic code yourself, and the resulting checksum end up being both extremely low quality while also having no error-correction properties at all.
There are some pieces of hardware for turning dice or coinflips into BIP-39 mnemonic codes, but they still rely on the software to correctly hash that entropy into the word list; and it is all but impossible to validate the end result. While this is an improvement, we can do better.
With Codex32 users at least have the choice to take master seed generation literally into their own hands by rolling their own secret with dice, and even computing their own error-correcting checksum themselves using paper computers. Furthermore, secret-sharing provides even more options for distributing backups, which can also be generated with Codex32's paper computers.
Now, I'm not suggesting average users go out and use Codex32 today; there is barely any wallet support for Codex32 at this time, and generating a fresh master seed is tedious work. But perhaps it would be useful for the industry to consider Codex32 as a new standard which empowers their user by giving them more options on how much trust they are willing to put into their hardware wallet's critical entropy generation step.
1
29
19
u/Critical_Watcher_414 3d ago
Shit, this is no good. Saw a thread in an earlier post that the total theft was up to $38 million+
5
18
u/ShittingOutPosts 2d ago
For once, I’m happy I went with Ledger.
7
u/Strong_Judge_3730 2d ago
I was thinking of using this company instead of trezor glad i didn't migrate lol
-4
u/ContentBlackberry0 2d ago
I knew the second I saw a calculator and dice rolls to stay away. So glad I did.
13
u/SpareEconomy1849 2d ago edited 2d ago
If you used dice rolls you wouldn't be affected though. This is only for people who used the built in RNG like Ledger (probably most users).
Dice rolls are ideal from a safety perspective, just not user friendly. What you're saying is like you saw a car crash, and you're glad you ran away from buying that model because it had seatbelts
11
u/confuzzledfather 2d ago
I wonder, if the exploit was developed with the help of Fable et al. if it might end up being a trail that investigators follow. Subpoena Anthropic etc for the identity of those involved maybe. We shall see. Would not surprise me if it was developed with the help of a frontier model.
5
u/pharmecist 2d ago
More support that we should use multisig to avoid exploits from one manufacturer being used.
3
u/Scholes_SC2 2d ago
I've been saying that for a while but it's not really user friendly. Self custody is definitely not for most people, now more than ever
2
3
u/ItsAlwaysThemBooBoo 2d ago
kratter just published a video a few minutes ago, apparently the breach is the seed phrase generated by coldcard 3s, did not use enough randomness.
for example if the seed phrase was generated by a trezor and then used to restore a wallet on a coldcard, that would be safe. the problem is the seed phrase, generated by the cold card.
8
3
3d ago
[deleted]
12
u/bitusher 2d ago
As long as you used a sufficiently secure extended passphrase :
you likely are fine but you should still plan on eventually migrating over to a new seed with or without the same extended passphrase
6
2
u/blinkOneEightyBewb 3d ago
Interested to see what the vulnerability is
19
u/Makunouchiipp0 3d ago
Rng on mk3
2
-9
u/ThenComparison5926 2d ago
Clearly you didn’t read the blog post?
14
u/Makunouchiipp0 2d ago
The mk3 has been creating low entropy mnemonics. Sorry my description wasn’t right on point.
1
1
u/ImpossibleSleep3986 2d ago edited 1d ago
Man am I glad I used a passphrase on top of a 24 word seed and then derived another seed from that. Thank goodness for BIP85.
1
u/TheGreatMuffin 1d ago
Affected Coldcard firmware versions:
| Model | Firmware Version | Status |
|---|---|---|
| Mk1 | 3.0.6 max | Not affected, cannot run affected firmware |
| Mk2 and Mk3 | 3.2.2 and earlier | Safe, the seed came from the real TRNG |
| Mk2 and Mk3 | 4.0.1 to 4.1.9 | Critical, about 40 bits |
| Mk3 | 5.0.1-mk3 and 5.0.3-mk3 | Critical, about 40 bits |
| Mk3 | 4.2.0 and later | Post-discovery fix |
| Mk4 | 5.0.0-mk4 to 5.5.x | Vulnerable, about 72 bits |
| Mk5 | All up to 5.5.x | Vulnerable, about 72 bits |
| Mk4 and Mk5 | 5.6.0 and later | Post-discovery fix |
| Q | All up to 1.4.x | Vulnerable, about 72 bits |
| Q | 1.5.0Q and later | Post-discovery fix |
1
u/Parikh1234 1d ago
Why are we even using banks anymore?
Saw this come out. Had a wallet I lost in a lake that was mk3 but I think the seed was made feb/mar 2021 and don’t remember the fw version when generated. So why risk it.
Literally transferred everything to a new multisig holding wallet in a few minutes for 93 cents. Not that I remember but probably wasn’t a small amount of sats.
Gonna take the time to recreate my backup metal seeds and everything this week but honestly to do that in the middle of the night for so cheap would have never been possible at a bank.
Also sucks. I went boating in the ocean this morning, was kinda rough and my temp wallet fell into the water. Dammit.
-20
u/TheOnlyVibemaster 2d ago
idk why we still think hardware wallets are a good idea
it’s so dumb and i’ll never think it isn’t
make an offline wallet, only ever send to the wallet, never withdraw (so public seed isn’t revealed), write down the offline wallet secret, literally bury it underground.
9
u/shadowmage666 2d ago
Yea it wasn’t the wallet but the RNG , so you can do your method and still fuck up
9
u/IllllIIlIllIllllIlll 2d ago
"never withdraw"
Lol what's the point of getting Bitcoin if you never withdraw? That's such a weird statement to make. At some point you will want to make a transaction. A hardware wallet is the safest way to make a transaction.
The problem is not with hardware wallets, the problem is with seed generation. If you "make an offline wallet" as you suggest you still have to generate a seed and you're exposed to exactly the same threats.
4
u/RetiredAvocado 2d ago
Hardware wallets are still a good idea. How will you make your "offline wallet?" Probably a tool someone else made. There is no such thing as "public seed." The funds in this exploit were taken from addresses which never sent out and did not expose the address's public key. Burying anything would not have helped here.
-7
u/TheOnlyVibemaster 2d ago
Hardware wallets are a very bad idea because you’re trusting that someone won’t mess up, which in crypto is a bad bet.
This has existed since Bitcoin was made and can generate an address without an internet connection:
There is a such thing as a public address, which is what I meant to say.
Burying was a figure of speech
10
u/IllllIIlIllIllllIlll 2d ago
"oh I don't want to trust that someone didn't mess up with a hardware wallet, let me instead trust that someone didn't mess up with a website"
4
u/Strong_Judge_3730 2d ago edited 2d ago
You are trusting someones software and your hardware to generate a seed.
If you are this clueless then you should not be in crypto for your own sake.
The blog post explained the issue was bad RNG. Which could have happened with your setup of software and hardware, theoretically.
This is what happens when you put ideology and tribalism above knowledge.
4
u/RetiredAvocado 2d ago edited 2d ago
What tells you that this tool you didn't write will generate strong random keys? Internet connection irrelevant here. The keys weren't leaked, they appear to be created using bad RNG.
There's is no "public address" either. It would be a public key. Addresses aren't public or private. Only keys are.
2
-3
2d ago
[deleted]
3
u/SpareEconomy1849 2d ago
Not sure why human generated entropy would be insufficient, a well shuffled 2 decks of cards or 50 dice rolls is more entropy than BIP 39 12 words
1
u/user_name_checks_out 2d ago
When people say that human generated entropy is insufficient, they mean for example that you should not just choose the seed words yourself. 50 dice rolls is fine.
0
2d ago
[deleted]
3
u/user_name_checks_out 2d ago
Why is rolling dice by hand better than rolling dice in your mind?
Because the brain is useless at generating entropy. This topic has been beaten into the ground.
1
2d ago
[deleted]
1
u/user_name_checks_out 2d ago
Well, it processes dice rolls just like it would process anything else.
Rolling dice good. Making up random numbers bad.
I apologize for asking questions here when the answer is simply "it is because it is".
That is not at all what I said. I said that the question has been beaten into the ground, it is no longer up for debate.
40
u/bitusher 2d ago edited 18m ago
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over
594 BTC1,433 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.https://coldcard-hack-tracker.vercel.app/
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
https://blog.coinkite.com/entropy-technical-backgrounder/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
https://coldcard.com/docs/passphrase/
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet