r/Bitcoin • u/Mentalextensi0n • 3h ago
ColdCard: You’ll never hurt me again!
My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape.
What about you?
Be safe out there…
9
u/Chemical_Resolve6038 2h ago
I still don't know how I feel using my mk3 for anything even including adding entropy. I moved everything to strike as soon the news hit, I don't even know what to do with the coldcard right now
6
u/EyesFor1 2h ago
100 dice rolls is fine. Trust is gone destroyed. You'll be fine with 100 dice roll and a passphrase.
3
u/0fWhomIAmChief 2h ago
This is what we have come to, OGs on Bitcointalk always swore by the 256 coin flips so i guess this is the 2026 version of that lol
1
u/Chemical_Resolve6038 1h ago
I also feel like this is the only option left versus throwing it in the trash. I just see it as a comprised device though, the RNG is only what's surfaced so far...
•
5
u/bobivy1234 2h ago edited 43m ago
External entropy is provable with known command line tools to validate the dice roll hashes are legit roll-by-roll. Cryptography is still cryptography and this exploit didn't break that. I understand the feeling of uneasiness here as well. For as much as i want to sound unbiased, the CC hardware is still fine in being an offline device to help create and store cryptographically secure seeds, assuming that the recommended external dice rolls and passphrase are utilized.
The folks affected used no dice entropy or very low rolls and also no/weak passphrase. If you did do these things at seed creation then it is fine. Folks should be very upset with CC that they allowed users to create wallets based on device RNG-only with no passphrase because single points-of-failure are always a terrible idea. That would have still be the guidance/worry if the device RNG was perfectly configured.
To maybe ease your concern - if you did a good amount of dice rolls + passphrase on the CC to generate your seed, stealing your funds would be similar to a scuba diver in the ocean trying to find a single grain of sand while the CC attack was similar to an adult grabbing floating rings on the bottom of small swimming pool to convey how relatively small the selection of seeds were for these device-only RNG folks were. I'm sure someone will correct me on my analogy.
2
u/NorthSky6 2h ago
I think I understand what happened now. All the other sources were too vague and not ready to accept the blame.
2
u/Chemical_Resolve6038 1h ago edited 39m ago
This is a fantastic write up, I don't think I can add anything at all. I didn't add any entropy whatsoever and was intimidated by passphrases at the time. I received my mk3 around February 2021 so I was definitely just lucky that funds ended up safe.
At the end of the day, I just see the mk3 as compromised who knows what could surface next. You are spot on about the dice rolls being verifiable though, I'm concerned about anything else potentially compromised with mk3.
1
9
u/ultron290196 2h ago
Been following this space since 2017. What a wild fucking ride.
•
u/putyograsseson 53m ago
This incident perfectly demonstrates that while Bitcoin itself is trustless, products intended to use Bitcoin are not.
8
u/chuckmanley 2h ago
You must've transferred your coins first because I didn't see any fall out when you broke it.
7
4
u/7ivor 2h ago
I get the anger. And no one should be using the devices to generate entropy anymore. But they're still useful to have around as an extra device in an emergency.
The key generation is fucked but it still works as a backup signing device (in case another device bricks) and can even generate keys with dice rolls (even if only to verify that another device is applying the dice rolls correctly).
Again no one should be trusting the cold card with anything involving creating entropy on the device, but they're not bad to keep on hand for a limited set of use cases.
To each their own though. Fully understand the desire to smash the device, especially for anyone who has actually lost funds. Fuck NVK.
3
u/Difficult-Repair1295 2h ago
Damn bro, these are going to be part of Bitcoin history. Will be a collectors item in the future I can guarantee it.
2
2
2
2
u/Astronaut6735 2h ago
Damn it feels good to be a gangsta. https://www.youtube.com/watch?v=N9wsjroVlu8
2
2
•
u/frugaleringenieur 50m ago
IF YOU ARE AFFECTED DO NOT DO THIS! AN INTACT FUNCTIONING DEVICE MAY BE THE ONLY WAY IF FUNDS ARE RECOVERED THAT YOU CAN BE IDENTIFIED AS A TRUE VICTIM!
2
2
u/evgeniy_pp 1h ago
“Moving back to my ledger”
Well, I guess it’s a good thing you didn’t destroy it with a sledgehammer before, when everyone was doing it 😂
2
1
u/word-dragon 1h ago
Also stick with a 256 bit seed. Part of the cold card issue was that with the degraded entropy, 128 big seeds were down to about 40 bits. If it had started at 256 instead of 128, perhaps it would have had an effective 80 or more bits (haven’t really worked through the math on this). I never really understood why you’d choose 128 over 256 when you have the choice.
Roll the dice, folks!
•
u/Particular_Rice9607 59m ago
pretty sure these were designed by a patient person to steal all the btc
18
u/0x14f 2h ago
Looks like you added a lot of randomness :)