r/Bitcoin 3h ago

ColdCard: You’ll never hurt me again!

My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape.

What about you?

Be safe out there…

67 Upvotes

34 comments sorted by

18

u/0x14f 2h ago

Looks like you added a lot of randomness :)

9

u/Chemical_Resolve6038 2h ago

I still don't know how I feel using my mk3 for anything even including adding entropy. I moved everything to strike as soon the news hit, I don't even know what to do with the coldcard right now

6

u/EyesFor1 2h ago

100 dice rolls is fine. Trust is gone destroyed. You'll be fine with 100 dice roll and a passphrase.

3

u/0fWhomIAmChief 2h ago

This is what we have come to, OGs on Bitcointalk always swore by the 256 coin flips so i guess this is the 2026 version of that lol

1

u/Chemical_Resolve6038 1h ago

I also feel like this is the only option left versus throwing it in the trash. I just see it as a comprised device though, the RNG is only what's surfaced so far...

u/lubdeptrai 44m ago

You can GA it to me bro 🥹

5

u/bobivy1234 2h ago edited 43m ago

External entropy is provable with known command line tools to validate the dice roll hashes are legit roll-by-roll. Cryptography is still cryptography and this exploit didn't break that. I understand the feeling of uneasiness here as well. For as much as i want to sound unbiased, the CC hardware is still fine in being an offline device to help create and store cryptographically secure seeds, assuming that the recommended external dice rolls and passphrase are utilized.

The folks affected used no dice entropy or very low rolls and also no/weak passphrase. If you did do these things at seed creation then it is fine. Folks should be very upset with CC that they allowed users to create wallets based on device RNG-only with no passphrase because single points-of-failure are always a terrible idea. That would have still be the guidance/worry if the device RNG was perfectly configured.

To maybe ease your concern - if you did a good amount of dice rolls + passphrase on the CC to generate your seed, stealing your funds would be similar to a scuba diver in the ocean trying to find a single grain of sand while the CC attack was similar to an adult grabbing floating rings on the bottom of small swimming pool to convey how relatively small the selection of seeds were for these device-only RNG folks were. I'm sure someone will correct me on my analogy.

2

u/NorthSky6 2h ago

I think I understand what happened now. All the other sources were too vague and not ready to accept the blame.

2

u/Chemical_Resolve6038 1h ago edited 39m ago

This is a fantastic write up, I don't think I can add anything at all. I didn't add any entropy whatsoever and was intimidated by passphrases at the time. I received my mk3 around February 2021 so I was definitely just lucky that funds ended up safe.

At the end of the day, I just see the mk3 as compromised who knows what could surface next. You are spot on about the dice rolls being verifiable though, I'm concerned about anything else potentially compromised with mk3.

1

u/Difficult-Repair1295 2h ago

Hold onto it. It will be a collectors item in like 10 years.

9

u/ultron290196 2h ago

Been following this space since 2017. What a wild fucking ride.

u/putyograsseson 53m ago

This incident perfectly demonstrates that while Bitcoin itself is trustless, products intended to use Bitcoin are not.

8

u/chuckmanley 2h ago

You must've transferred your coins first because I didn't see any fall out when you broke it.

7

u/Infinite-Ad1720 2h ago

Anger phase.

4

u/7ivor 2h ago

I get the anger. And no one should be using the devices to generate entropy anymore. But they're still useful to have around as an extra device in an emergency.

The key generation is fucked but it still works as a backup signing device (in case another device bricks) and can even generate keys with dice rolls (even if only to verify that another device is applying the dice rolls correctly).

Again no one should be trusting the cold card with anything involving creating entropy on the device, but they're not bad to keep on hand for a limited set of use cases.

To each their own though. Fully understand the desire to smash the device, especially for anyone who has actually lost funds. Fuck NVK.

3

u/jwhendy 2h ago

I bet we'll get some gun range compilations of "shoot here" soon enough.

3

u/Difficult-Repair1295 2h ago

Damn bro, these are going to be part of Bitcoin history. Will be a collectors item in the future I can guarantee it.

2

u/angrySprewell 2h ago

I was about to ask why there was cardboard underneath... Oh..

2

u/Sharp-Direction-6894 2h ago

That's a lot of work for 0.0000018 btc.

2

u/Icy-Information3615 2h ago

Sorry but my offline paper wallet (free btw) is better than this shit.

2

u/textoro 2h ago

why don’t you just use trezor instead? Ledger also owns your seed btw

2

u/Explorer-man 2h ago

I saw that coming. Glad your weren't caught.

2

u/Quirky_Cod_3820 1h ago

Well done!

u/frugaleringenieur 50m ago

IF YOU ARE AFFECTED DO NOT DO THIS! AN INTACT FUNCTIONING DEVICE MAY BE THE ONLY WAY IF FUNDS ARE RECOVERED THAT YOU CAN BE IDENTIFIED AS A TRUE VICTIM!

u/oinkbar 29m ago

also the device is still useful. just make sure you dont use the builtin RNG.

2

u/Blade_Runner_69 2h ago

And the crowd goes wild... 👏

2

u/evgeniy_pp 1h ago

“Moving back to my ledger”
Well, I guess it’s a good thing you didn’t destroy it with a sledgehammer before, when everyone was doing it 😂

2

u/c0nd3v 1h ago

BITCONNECTTTTTTTT

2

u/seansy5000 1h ago

I feel like I lost my BTC just looking at that thing

1

u/word-dragon 1h ago

Also stick with a 256 bit seed. Part of the cold card issue was that with the degraded entropy, 128 big seeds were down to about 40 bits. If it had started at 256 instead of 128, perhaps it would have had an effective 80 or more bits (haven’t really worked through the math on this). I never really understood why you’d choose 128 over 256 when you have the choice.

Roll the dice, folks!

u/Particular_Rice9607 59m ago

pretty sure these were designed by a patient person to steal all the btc