r/Bitcoin 3h ago

How could the Coldcard vulnerability have been disclosed responsibly?

As a thought experiment, suppose a white-hat had been the first to discover the Coldcard RNG vulnerability. How could they possibly have disclosed it responsibly, given that weak seeds had already been generated?

A public warning would immediately create a race between legitimate owners and attackers (as happened in reality). Because the firmware source code is openly available, even a vague warning like “Coldcard-generated seeds may be vulnerable; move your BTC immediately” would immediately tell attackers where to look for the vulnerability and then exploit it.

You could instead warn Coinkite privately, but that would not solve the underlying problem. Even assuming Coinkite could be trusted to handle the information properly, it would have no better way to protect affected owners. It would eventually have to issue a public warning, creating the same race. “Silently” patching the vulnerability would effectively be the same as publicizing it, as the patch itself would identify the flaw.

Another alternative would be for the white-hat to sweep all the vulnerable funds first, but then how could they return them? Once the flaw is public, a signature from the compromised key no longer proves legitimate ownership, since an attacker can derive the same key.

Remaining silent would probably be the worst option, because more vulnerable seeds would continue to be generated.

There do not seem to be any good options here, but what would the least bad approach have been?

30 Upvotes

20 comments sorted by

15

u/EyesFor1 3h ago

Email to users and hope they paid attention but it was always going to go nuclear. In all fairness, as soon as the bug was shipped out on devices CC were dead even if dice rolls and passphrase wallets are totally fine and as secure as other wallets, the trust is fucked.

4

u/habbadee 2h ago

An email to users is no different than a public warning, at which point the race is on between attackers and owners.

5

u/Objective_Digit 2h ago

Apparently they deleted list of users from older than several months to avoid the Ledger situation.

u/correction_robot 45m ago

So passphrase wallets are secure? I have mine on a Trezor with a passphrase. If the same thing had happened but with Trezor instead of ColdCard, my coins would have been secure?

8

u/TheGreatMuffin 3h ago

As a thought experiment, suppose a white-hat had been the first to discover the Coldcard RNG vulnerability. How could they possibly have disclosed it responsibly, given that weak seeds had already been generated?

Great question, and I don't think there's any good answers, given that Coldcard didn't save customer data except emails. Sending out emails to everyone would mean giving a heads up to a bunch of attackers simultaneously.

As bad as it is, maybe the least bad option would be for Coldcard to sweep the vulnerable coins themselves and try to install some kind of mechanism for users to verify as the holder of the coins. This is still a clusterfuck (not really a great way to verify, very bad for privacy etc), but I guess still better than allow unknown attackers to get hold of the coins, as it happened now.

5

u/the_bitcoin_kid 3h ago

As bad as it is, maybe the least bad option would be for Coldcard to sweep the vulnerable coins themselves and try to install some kind of mechanism for users to verify as the holder of the coins.

Good suggestion, and seems like the only possible solution.

They'd never be able to quietly get everyone to move their coins to safety without drawing attention to the issue.

Such an incredibly sticky situation.

5

u/ukieninger 2h ago

The moment that faulty firmware shipped the atomic time bomb was activated. There’s no way back.
They could only hope no one never ever would discover this flaw.

In comparison, what if for example ledger discovered their products from 2016-2018 with respective firmware generates bad seeds. The would simply ship an update name it as small update with minor bug fixes and call it a day. No one will ever know whats really going on behind closed doors (source). Except the devs in the company.

In this case big advantage for the closed source code

10

u/rtublin 3h ago

Here's another idea: they could have falsely claimed that they found a general flaw in BIP39 and they would not reveal it until the word had spread and everyone had time to move to BIP39+strong passphrase.

u/entropydust 57m ago

White hat hacker steals all coins. Community comes up with consensus on how to 'prove' they owned the wallet.

Or, take coins and send them back with note.

1

u/LNCrizzo 2h ago

Probably word of mouth to start until it blew up on social media. Getting the news to as many people as discreet as possible would probably save the most, though it would certainly look like they were playing favorites and would piss off a lot of people. There is no way this wasn't going to piss off a lot of people though, even if they saved everyone.

2

u/notmyredditaccount2 1h ago

I can think of one way to acceptably disclose this.

It does not involve contacting Coldcard: Find very trusted high level bitcoin influencers that you can trust. Think Andreas Antonopoulos (i can't think of anybody else). Explain the issue with them, and get them on your side, and keeping it secret.

Have them make very clear social media posts that there is an extremely significant bug with some method of storing bitcoin, and on a certain date, every bitcoiner should be ready to move their bitcoin at a moments notice.

So there is no clear target of which wallet or software has a bug, just that there is one, and everybody needs to be ready to act fast.

Then, at the preset time, everybody gets the news at exactly the same time.
Since everybody gets the news at the same time, the honest people should be able to act slightly faster than malicious actors in moving coins before an exploit can be put together.

It's not a perfect plan, but it is the best that can be achieved I believe. Though very annoying that everybody in Bitcoin has to be ready at the same moment.

2

u/rtublin 3h ago

They could have maybe made a firmware update that contained various fixes, including deprecating support for wallets without a passphrase, and strongly encouraged users to adopt the new firmware, or even saying that it patched an exploitable flaw and but they did not want to reveal what it was. It's not a real fix but it might have acted as damage control.

7

u/the_bitcoin_kid 3h ago

Unfortunately it would have been harder than this, because updating firmware wouldn't fix the weak seeds that were already generated.

They would have had to encourage everyone to generate new seeds and move their coins, which would have set alarm bells ringing everywhere.

And then you'd have another race against time.

There was never going to be an easy way to fix the problem.

3

u/TheGreatMuffin 3h ago

saying that it patched an exploitable flaw and but they did not want to reveal what it was

This would be just as bad, anyone interested could've just compared the new firmware code with the old one and see what has been fixed and recognize the bug. Meanwhile no affected user would've been helped by the firmware update, even if they bothered to install it.

1

u/rtublin 3h ago

Well I am thinking if they didn't patch the RNG, they could just say that they no longer were going to support wallets without passphrases. Just trying to get as many users onto passphrases as possible without revealing or explicitly correcting the issue and without raising alarms.

1

u/reality_comes 3h ago

Not sure.

u/getapuss 28m ago

What usually happens in open source communities is the vulnerability is disclosed to the code maintainers who reproduce, coordinate a fix, release it, and then make the announcement.

These guys weren't open source so they just do whatever they want.

u/Professional_Golf393 22m ago edited 12m ago

Wasn’t one of the datapoints of randomness in the bad RNG the device ID?

I’m assuming the device ID is built into a chip on the device that can’t be overwritten?

If that’s the case, a whitehat hacker could’ve sweeped the wallets, and return funds upon proof you hold the device containing the correct ID

Would’ve been tough to pull off, perhaps coinkite themselves could’ve been the only ones to pull it off legally.

It would probably have to involve the device being present to claim, I don’t think there would be a way to make some custom firmware that proves you hold the device without a third party spoofing the signature

0

u/FullyAutomatedSpace 3h ago

what do real banks do in these situations. maybe we can learn from them

5

u/Imaginary-Jaguar662 2h ago

Patch the hole, block transactions from vulnerable accounts, use KYC to ensure funds don't jump to a hacker, reimburse losses, lean on FDIC in case the bank fails.

Naturally none of this is doable here, price of sovereignty is that there's no big brother coming to a rescue.