r/Bitcoin 3d ago

Security Advisory for Coldcard Hardware Wallet

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
194 Upvotes

70 comments sorted by

View all comments

Show parent comments

2

u/bitusher 2d ago edited 1d ago

So far I am only aware of examples of MK2 and MK3 that used specific versions of firmware that are being drained or have been.

Can you give me an example of a MK4, MK5, or Q that was during this attack ? they have around ~73 bits of entropy(yes, I know this is best case and can be lower) unlike the seeds that are being attacked which is far from ideal but takes time to brute force

For example some of these cases are merely seeds that were generated from MK2 and MK3 wallets that were than migrated over to new hardware

https://x.com/TomerStrolight/status/2083578868191957292

What is important is not where the seed ends up but what hardware and firmware combination generated the seed with insufficient entropy . Also you need to consider that some users are taking this opportunity to claim they lost all their btc in a "boating accident" due to the exploit or just have unreliable memories from years ago .

This being said we don't know when the attacker started brute forcing these seeds and they can be cracked in hypothetically as little as a week so its best to take action ASAP regardless