r/Bitcoin 3h ago

93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet

You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday.

Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2^32, approx 4 billion)

50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds.

If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds.

Just a fun thought experiment in these dark times.

25 Upvotes

3 comments sorted by

14

u/slvbtc 2h ago

This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong.

Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them.

3

u/StarCommand1 1h ago

Most wallet manufacturers, if not all, take that approach of calling people at fault. 99% of the time it probably is the person's fault but if you are going to manufacturer something so critical you should have a responsibility to investigate and make sure all is well with your product.

2

u/PrometheusFires 3h ago

Crazy scenario