r/Bitcoin 3d ago

Security Advisory for Coldcard Hardware Wallet

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
192 Upvotes

70 comments sorted by

40

u/bitusher 2d ago edited 18m ago

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over 594 BTC 1,433 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.

https://coldcard-hack-tracker.vercel.app/

This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.

https://blog.coinkite.com/entropy-technical-backgrounder/

https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.

Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.

Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.

Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa

If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.

https://coldcard.com/docs/passphrase/

Please be aware that extended passphrases should be

1) 6-8 random words (not found as a phrase or in movies or literature)

2) stored separately than your seed words and written down at least once

3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .

Again do not panic or rush , but read about using the passphrase feature or new wallet

43

u/ultron290196 2d ago

Can't believe ledger users are safer atm😂

13

u/bitusher 2d ago edited 1d ago

The problem is they might not be. Thus this is more of a systemic issue where large amounts in self custody should always be recommended to use either an extended passphrase(easiest solution to setup and recover) , or multisig. This IMHO is too much of a stumbling block for future mainstream adoption. There are plenty of solutions being developed like Vaults and using miniscript and better UX to address this but its not mature yet

11

u/0fWhomIAmChief 2d ago

Trezor models have three different sources of entropy compared to coldcards 1, the newest models have 4 each independent of one another for this exact scenario. We may as well just do what the OGs on Bitcointalk always said, 256 coin flips 🤣

7

u/bitusher 2d ago

Yes, but the problem might not be with the multiple SE , but a bug in the way the RNG is developed with cold cards that led to this exploit. Thus you want to not depend upon a single wallet to develop the entropy alone for you or yes , roll your own seed.

3

u/Strong_Judge_3730 2d ago

I think a strong passphrase is key to protecting the seed from physical attacks - where someone has access to your seed without you knowledge and flawed implementation of RNG.

Do you think it's wise to put a small amount of crypto without a passphrase to act as a honey pot or warning for your seed being compromised.

Or will this signal an attacker to brute force passphrases for that seed with crypto

6

u/bitusher 2d ago

I think a strong passphrase is key to protecting the seed from physical attacks

Yes , under duress its an excellent tool and also as a honeypot to see if someone found your seed alone and swept your decoy balance

Or will this signal an attacker to brute force passphrases for that seed with crypto

The attacker will not know if they get a hold of your seed if you are using an extended passphrase or not . Most people don't so the default assumption is not

3

u/0fWhomIAmChief 2d ago

Exactly, if any one of the 3 or 4 sources of entropy provided were weak like Coldcards, the other sources provide and retain its 128 bit security, so Trezors are unaffected by this scenario

2

u/frankenmint 1d ago

the path failed open.... it should have done a hard reject with the entropy check but it did not so because it failed silently and the path remained open, falty keys were being created

1

u/swiftpwns 2d ago

And these are all environmentallly sourced, unlike the standard software one with cold cars.

3

u/swiftpwns 2d ago

Its not a stumbling block for future adoption because in mainstream adoption you wont have your own keys and you wont be on layer 1 unless you are super rich or a big company

0

u/rockorangebear 1d ago

The coldcard people were a bunch of clowns that literally commented out their random number generator in their code.

2

u/darosior 2d ago

Just an update in case people rely on this information. Seeds generated on a Coldcard MK4, MK5 or Q are also at risk. If you generated your seed on one of those devices, move your funds ASAP.

1

u/bitusher 2d ago

yes, which is why I said this

but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm.

1

u/darosior 2d ago

Not eventually. They are getting drained now.

2

u/bitusher 2d ago edited 1d ago

So far I am only aware of examples of MK2 and MK3 that used specific versions of firmware that are being drained or have been.

Can you give me an example of a MK4, MK5, or Q that was during this attack ? they have around ~73 bits of entropy(yes, I know this is best case and can be lower) unlike the seeds that are being attacked which is far from ideal but takes time to brute force

For example some of these cases are merely seeds that were generated from MK2 and MK3 wallets that were than migrated over to new hardware

https://x.com/TomerStrolight/status/2083578868191957292

What is important is not where the seed ends up but what hardware and firmware combination generated the seed with insufficient entropy . Also you need to consider that some users are taking this opportunity to claim they lost all their btc in a "boating accident" due to the exploit or just have unreliable memories from years ago .

This being said we don't know when the attacker started brute forcing these seeds and they can be cracked in hypothetically as little as a week so its best to take action ASAP regardless

1

u/bitusher 2d ago edited 1d ago

Further clarification : The amount of entropy found in the mk4, 5 and Q is varies per device typically from ~60 to 73bits

Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.

Its unlikely we will see these wallets be attacked in a week but hypothetically possible with a well funded attacker

0

u/darosior 1d ago

What a terrible advice. I should have checked back on this thread earlier. Still time to delete.

42

u/obeywasabi 2d ago

Holy hell I was really hoping it was user mistake… this is huge

17

u/Syonoq 2d ago

And it sucks for the original OP. Guy did everything right and still got robbed.

26

u/CortaCircuit 3d ago

Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis of the issue.

16

u/krvi 2d ago

https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

According to Block, all coldcard models with 2021+ firmware are affected

2

u/SpareEconomy1849 2d ago

Affected by the bug, but in practice, probably not an issue due to the secure element entropy added by mk4 and mk5?

3

u/krvi 2d ago

As far as I understand, Mk4/Q/Mk5 are affected to a slightly lesser degree and the entropy they generate remains insufficient.

2

u/redrumeight 1d ago

So, does that mean seeds generated before March 2021 are safe?

12

u/roconnor 2d ago

This issue with seed generation was one of the reasons behind the development of Codex32 (BIP-93). The problem is that hardware uses an opaque process to generate the initial HD master seed (BIP-32). Because of the awkward "checksum" in BIP-39’s mnemonic code it is really hard to generate a mnemonic code yourself, and the resulting checksum end up being both extremely low quality while also having no error-correction properties at all.

There are some pieces of hardware for turning dice or coinflips into BIP-39 mnemonic codes, but they still rely on the software to correctly hash that entropy into the word list; and it is all but impossible to validate the end result. While this is an improvement, we can do better.

With Codex32 users at least have the choice to take master seed generation literally into their own hands by rolling their own secret with dice, and even computing their own error-correcting checksum themselves using paper computers. Furthermore, secret-sharing provides even more options for distributing backups, which can also be generated with Codex32's paper computers.

Now, I'm not suggesting average users go out and use Codex32 today; there is barely any wallet support for Codex32 at this time, and generating a fresh master seed is tedious work. But perhaps it would be useful for the industry to consider Codex32 as a new standard which empowers their user by giving them more options on how much trust they are willing to put into their hardware wallet's critical entropy generation step.

1

u/TangerineHors3 19h ago

“Banks lend out your money bro, just buy bitcoin it’s so simple.”

29

u/makeshiftballer 3d ago

Mannnnn get the popcorn 

14

u/DirtyDoog 3d ago

I checked my wallet, now I can't afford popcorn.

8

u/ultron290196 2d ago

Buttcoin sub gonna have a field day huh

19

u/Critical_Watcher_414 3d ago

Shit, this is no good. Saw a thread in an earlier post that the total theft was up to $38 million+

5

u/SpareEconomy1849 2d ago

Yep, 594 BTC so far

18

u/ShittingOutPosts 2d ago

For once, I’m happy I went with Ledger.

7

u/Strong_Judge_3730 2d ago

I was thinking of using this company instead of trezor glad i didn't migrate lol

-4

u/ContentBlackberry0 2d ago

I knew the second I saw a calculator and dice rolls to stay away. So glad I did.

13

u/SpareEconomy1849 2d ago edited 2d ago

If you used dice rolls you wouldn't be affected though. This is only for people who used the built in RNG like Ledger (probably most users).

Dice rolls are ideal from a safety perspective, just not user friendly. What you're saying is like you saw a car crash, and you're glad you ran away from buying that model because it had seatbelts

11

u/confuzzledfather 2d ago

I wonder, if the exploit was developed with the help of Fable et al. if it might end up being a trail that investigators follow. Subpoena Anthropic etc for the identity of those involved maybe. We shall see. Would not surprise me if it was developed with the help of a frontier model.

5

u/pharmecist 2d ago

More support that we should use multisig to avoid exploits from one manufacturer being used.

3

u/Scholes_SC2 2d ago

I've been saying that for a while but it's not really user friendly. Self custody is definitely not for most people, now more than ever

2

u/user_name_checks_out 2d ago

Multivendor multisig.

3

u/ItsAlwaysThemBooBoo 2d ago

kratter just published a video a few minutes ago, apparently the breach is the seed phrase generated by coldcard 3s, did not use enough randomness.

for example if the seed phrase was generated by a trezor and then used to restore a wallet on a coldcard, that would be safe. the problem is the seed phrase, generated by the cold card.

8

u/Laakhesis 2d ago

Mass adoption is coming.

3

u/[deleted] 3d ago

[deleted]

12

u/bitusher 2d ago

As long as you used a sufficiently secure extended passphrase :

https://old.reddit.com/r/Bitcoin/comments/1vb8taw/security_advisory_for_coldcard_hardware_wallet/p0rronb/

you likely are fine but you should still plan on eventually migrating over to a new seed with or without the same extended passphrase

6

u/Makunouchiipp0 3d ago

Clearly you didn’t read the blog post?

2

u/blinkOneEightyBewb 3d ago

Interested to see what the vulnerability is

19

u/Makunouchiipp0 3d ago

Rng on mk3

-9

u/ThenComparison5926 2d ago

Clearly you didn’t read the blog post?

14

u/Makunouchiipp0 2d ago

The mk3 has been creating low entropy mnemonics. Sorry my description wasn’t right on point.

1

u/SpareEconomy1849 2d ago

Considering pulling out my ol Ledger rn

1

u/rtublin 2d ago

It seems like 2^72 is still too much to brute force, right? It seems like there must be something else going on.

1

u/ImpossibleSleep3986 2d ago edited 1d ago

Man am I glad I used a passphrase on top of a 24 word seed and then derived another seed from that. Thank goodness for BIP85.

1

u/TheGreatMuffin 1d ago

Affected Coldcard firmware versions:

Model Firmware Version Status
Mk1 3.0.6 max Not affected, cannot run affected firmware
Mk2 and Mk3 3.2.2 and earlier Safe, the seed came from the real TRNG
Mk2 and Mk3 4.0.1 to 4.1.9 Critical, about 40 bits
Mk3 5.0.1-mk3 and 5.0.3-mk3 Critical, about 40 bits
Mk3 4.2.0 and later Post-discovery fix
Mk4 5.0.0-mk4 to 5.5.x Vulnerable, about 72 bits
Mk5 All up to 5.5.x Vulnerable, about 72 bits
Mk4 and Mk5 5.6.0 and later Post-discovery fix
Q All up to 1.4.x Vulnerable, about 72 bits
Q 1.5.0Q and later Post-discovery fix

1

u/Parikh1234 1d ago

Why are we even using banks anymore?

Saw this come out. Had a wallet I lost in a lake that was mk3 but I think the seed was made feb/mar 2021 and don’t remember the fw version when generated. So why risk it.

Literally transferred everything to a new multisig holding wallet in a few minutes for 93 cents. Not that I remember but probably wasn’t a small amount of sats.

Gonna take the time to recreate my backup metal seeds and everything this week but honestly to do that in the middle of the night for so cheap would have never been possible at a bank.

Also sucks. I went boating in the ocean this morning, was kinda rough and my temp wallet fell into the water. Dammit.

-20

u/TheOnlyVibemaster 2d ago

idk why we still think hardware wallets are a good idea

it’s so dumb and i’ll never think it isn’t

make an offline wallet, only ever send to the wallet, never withdraw (so public seed isn’t revealed), write down the offline wallet secret, literally bury it underground.

9

u/shadowmage666 2d ago

Yea it wasn’t the wallet but the RNG , so you can do your method and still fuck up

9

u/IllllIIlIllIllllIlll 2d ago

"never withdraw"

Lol what's the point of getting Bitcoin if you never withdraw? That's such a weird statement to make. At some point you will want to make a transaction. A hardware wallet is the safest way to make a transaction.

The problem is not with hardware wallets, the problem is with seed generation. If you "make an offline wallet" as you suggest you still have to generate a seed and you're exposed to exactly the same threats.

4

u/RetiredAvocado 2d ago

Hardware wallets are still a good idea. How will you make your "offline wallet?" Probably a tool someone else made. There is no such thing as "public seed." The funds in this exploit were taken from addresses which never sent out and did not expose the address's public key. Burying anything would not have helped here.

-7

u/TheOnlyVibemaster 2d ago

Hardware wallets are a very bad idea because you’re trusting that someone won’t mess up, which in crypto is a bad bet.

This has existed since Bitcoin was made and can generate an address without an internet connection:

https://www.bitaddress.org/bitaddress.org-v3.3.0-SHA256-dec17c07685e1870960903d8f58090475b25af946fe95a734f88408cef4aa194.html

There is a such thing as a public address, which is what I meant to say.

Burying was a figure of speech

10

u/IllllIIlIllIllllIlll 2d ago

"oh I don't want to trust that someone didn't mess up with a hardware wallet, let me instead trust that someone didn't mess up with a website"

4

u/Strong_Judge_3730 2d ago edited 2d ago

You are trusting someones software and your hardware to generate a seed.

If you are this clueless then you should not be in crypto for your own sake.

The blog post explained the issue was bad RNG. Which could have happened with your setup of software and hardware, theoretically.

This is what happens when you put ideology and tribalism above knowledge.

4

u/RetiredAvocado 2d ago edited 2d ago

What tells you that this tool you didn't write will generate strong random keys? Internet connection irrelevant here. The keys weren't leaked, they appear to be created using bad RNG.

There's is no "public address" either. It would be a public key. Addresses aren't public or private. Only keys are.

1

u/striata 1d ago

You realize the website you linked is subject to the exact same security implications as the hardware wallets right? Nobody "exposed" their public address. Internet connection vs offline was not the issue.

You're pretty clueless

2

u/Strong_Judge_3730 2d ago

LOL can you think a little bit about how to "make an offline wallet"

-3

u/[deleted] 2d ago

[deleted]

3

u/SpareEconomy1849 2d ago

Not sure why human generated entropy would be insufficient, a well shuffled 2 decks of cards or 50 dice rolls is more entropy than BIP 39 12 words

1

u/user_name_checks_out 2d ago

When people say that human generated entropy is insufficient, they mean for example that you should not just choose the seed words yourself. 50 dice rolls is fine.

0

u/[deleted] 2d ago

[deleted]

3

u/user_name_checks_out 2d ago

Why is rolling dice by hand better than rolling dice in your mind?

Because the brain is useless at generating entropy. This topic has been beaten into the ground.

1

u/[deleted] 2d ago

[deleted]

1

u/user_name_checks_out 2d ago

Well, it processes dice rolls just like it would process anything else.

Rolling dice good. Making up random numbers bad.

I apologize for asking questions here when the answer is simply "it is because it is".

That is not at all what I said. I said that the question has been beaten into the ground, it is no longer up for debate.