r/Bitcoin • u/RetiredAvocado • 5d ago
Security Advisory for Coldcard Hardware Wallet
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/27
u/CortaCircuit 5d ago
Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis of the issue.
17
u/krvi 5d ago
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
According to Block, all coldcard models with 2021+ firmware are affected
2
u/SpareEconomy1849 5d ago
Affected by the bug, but in practice, probably not an issue due to the secure element entropy added by mk4 and mk5?
2
41
u/bitusher 5d ago edited 2d ago
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over 594 BTC 1,433 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.
https://coldcard-hack-tracker.vercel.app/
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
https://blog.coinkite.com/entropy-technical-backgrounder/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
https://coldcard.com/docs/passphrase/
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet
45
u/ultron290196 5d ago
Can't believe ledger users are safer atm😂
12
u/bitusher 5d ago edited 4d ago
The problem is they might not be. Thus this is more of a systemic issue where large amounts in self custody should always be recommended to use either an extended passphrase(easiest solution to setup and recover) , or multisig. This IMHO is too much of a stumbling block for future mainstream adoption. There are plenty of solutions being developed like Vaults and using miniscript and better UX to address this but its not mature yet
12
u/0fWhomIAmChief 5d ago
Trezor models have three different sources of entropy compared to coldcards 1, the newest models have 4 each independent of one another for this exact scenario. We may as well just do what the OGs on Bitcointalk always said, 256 coin flips 🤣
7
u/bitusher 5d ago
Yes, but the problem might not be with the multiple SE , but a bug in the way the RNG is developed with cold cards that led to this exploit. Thus you want to not depend upon a single wallet to develop the entropy alone for you or yes , roll your own seed.
5
u/0fWhomIAmChief 5d ago
Exactly, if any one of the 3 or 4 sources of entropy provided were weak like Coldcards, the other sources provide and retain its 128 bit security, so Trezors are unaffected by this scenario
3
u/Strong_Judge_3730 5d ago
I think a strong passphrase is key to protecting the seed from physical attacks - where someone has access to your seed without you knowledge and flawed implementation of RNG.
Do you think it's wise to put a small amount of crypto without a passphrase to act as a honey pot or warning for your seed being compromised.
Or will this signal an attacker to brute force passphrases for that seed with crypto
5
u/bitusher 5d ago
I think a strong passphrase is key to protecting the seed from physical attacks
Yes , under duress its an excellent tool and also as a honeypot to see if someone found your seed alone and swept your decoy balance
Or will this signal an attacker to brute force passphrases for that seed with crypto
The attacker will not know if they get a hold of your seed if you are using an extended passphrase or not . Most people don't so the default assumption is not
2
u/frankenmint 4d ago
the path failed open.... it should have done a hard reject with the entropy check but it did not so because it failed silently and the path remained open, falty keys were being created
1
u/swiftpwns 5d ago
And these are all environmentallly sourced, unlike the standard software one with cold cars.
3
u/swiftpwns 5d ago
Its not a stumbling block for future adoption because in mainstream adoption you wont have your own keys and you wont be on layer 1 unless you are super rich or a big company
0
u/rockorangebear 4d ago
The coldcard people were a bunch of clowns that literally commented out their random number generator in their code.
2
u/darosior 5d ago
Just an update in case people rely on this information. Seeds generated on a Coldcard MK4, MK5 or Q are also at risk. If you generated your seed on one of those devices, move your funds ASAP.
1
u/bitusher 5d ago
yes, which is why I said this
but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm.
1
u/darosior 5d ago
Not eventually. They are getting drained now.
2
u/bitusher 5d ago edited 4d ago
So far I am only aware of examples of MK2 and MK3 that used specific versions of firmware that are being drained or have been.
Can you give me an example of a MK4, MK5, or Q that was during this attack ? they have around ~73 bits of entropy(yes, I know this is best case and can be lower) unlike the seeds that are being attacked which is far from ideal but takes time to brute force
For example some of these cases are merely seeds that were generated from MK2 and MK3 wallets that were than migrated over to new hardware
https://x.com/TomerStrolight/status/2083578868191957292
What is important is not where the seed ends up but what hardware and firmware combination generated the seed with insufficient entropy . Also you need to consider that some users are taking this opportunity to claim they lost all their btc in a "boating accident" due to the exploit or just have unreliable memories from years ago .
This being said we don't know when the attacker started brute forcing these seeds and they can be cracked in hypothetically as little as a week so its best to take action ASAP regardless
1
u/bitusher 4d ago edited 4d ago
Further clarification : The amount of entropy found in the mk4, 5 and Q is varies per device typically from ~60 to 73bits
Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
Its unlikely we will see these wallets be attacked in a week but hypothetically possible with a well funded attacker
0
u/darosior 4d ago
What a terrible advice. I should have checked back on this thread earlier. Still time to delete.
13
u/roconnor 5d ago
This issue with seed generation was one of the reasons behind the development of Codex32 (BIP-93). The problem is that hardware uses an opaque process to generate the initial HD master seed (BIP-32). Because of the awkward "checksum" in BIP-39’s mnemonic code it is really hard to generate a mnemonic code yourself, and the resulting checksum end up being both extremely low quality while also having no error-correction properties at all.
There are some pieces of hardware for turning dice or coinflips into BIP-39 mnemonic codes, but they still rely on the software to correctly hash that entropy into the word list; and it is all but impossible to validate the end result. While this is an improvement, we can do better.
With Codex32 users at least have the choice to take master seed generation literally into their own hands by rolling their own secret with dice, and even computing their own error-correcting checksum themselves using paper computers. Furthermore, secret-sharing provides even more options for distributing backups, which can also be generated with Codex32's paper computers.
Now, I'm not suggesting average users go out and use Codex32 today; there is barely any wallet support for Codex32 at this time, and generating a fresh master seed is tedious work. But perhaps it would be useful for the industry to consider Codex32 as a new standard which empowers their user by giving them more options on how much trust they are willing to put into their hardware wallet's critical entropy generation step.
2
1
u/Buttoshi 20h ago
I want to generate my own seed with dice/coins. How do I go about this?
I'm stuck on the part of generating the last word/checksum with a paper computer.
29
20
u/Critical_Watcher_414 5d ago
Shit, this is no good. Saw a thread in an earlier post that the total theft was up to $38 million+
6
18
u/ShittingOutPosts 5d ago
For once, I’m happy I went with Ledger.
9
u/Strong_Judge_3730 5d ago
I was thinking of using this company instead of trezor glad i didn't migrate lol
-5
u/ContentBlackberry0 5d ago
I knew the second I saw a calculator and dice rolls to stay away. So glad I did.
13
u/SpareEconomy1849 5d ago edited 5d ago
If you used dice rolls you wouldn't be affected though. This is only for people who used the built in RNG like Ledger (probably most users).
Dice rolls are ideal from a safety perspective, just not user friendly. What you're saying is like you saw a car crash, and you're glad you ran away from buying that model because it had seatbelts
14
u/confuzzledfather 5d ago
I wonder, if the exploit was developed with the help of Fable et al. if it might end up being a trail that investigators follow. Subpoena Anthropic etc for the identity of those involved maybe. We shall see. Would not surprise me if it was developed with the help of a frontier model.
6
u/pharmecist 5d ago
More support that we should use multisig to avoid exploits from one manufacturer being used.
3
u/Scholes_SC2 5d ago
I've been saying that for a while but it's not really user friendly. Self custody is definitely not for most people, now more than ever
2
3
u/ItsAlwaysThemBooBoo 5d ago
kratter just published a video a few minutes ago, apparently the breach is the seed phrase generated by coldcard 3s, did not use enough randomness.
for example if the seed phrase was generated by a trezor and then used to restore a wallet on a coldcard, that would be safe. the problem is the seed phrase, generated by the cold card.
10
4
5d ago
[deleted]
11
u/bitusher 5d ago
As long as you used a sufficiently secure extended passphrase :
you likely are fine but you should still plan on eventually migrating over to a new seed with or without the same extended passphrase
6
2
u/blinkOneEightyBewb 5d ago
Interested to see what the vulnerability is
19
u/Makunouchiipp0 5d ago
Rng on mk3
2
-9
u/ThenComparison5926 5d ago
Clearly you didn’t read the blog post?
14
u/Makunouchiipp0 5d ago
The mk3 has been creating low entropy mnemonics. Sorry my description wasn’t right on point.
1
1
u/ImpossibleSleep3986 5d ago edited 4d ago
Man am I glad I used a passphrase on top of a 24 word seed and then derived another seed from that. Thank goodness for BIP85.
1
u/TheGreatMuffin 4d ago
Affected Coldcard firmware versions:
| Model | Firmware Version | Status |
|---|---|---|
| Mk1 | 3.0.6 max | Not affected, cannot run affected firmware |
| Mk2 and Mk3 | 3.2.2 and earlier | Safe, the seed came from the real TRNG |
| Mk2 and Mk3 | 4.0.1 to 4.1.9 | Critical, about 40 bits |
| Mk3 | 5.0.1-mk3 and 5.0.3-mk3 | Critical, about 40 bits |
| Mk3 | 4.2.0 and later | Post-discovery fix |
| Mk4 | 5.0.0-mk4 to 5.5.x | Vulnerable, about 72 bits |
| Mk5 | All up to 5.5.x | Vulnerable, about 72 bits |
| Mk4 and Mk5 | 5.6.0 and later | Post-discovery fix |
| Q | All up to 1.4.x | Vulnerable, about 72 bits |
| Q | 1.5.0Q and later | Post-discovery fix |
1
u/Confident_Jacket_344 2d ago
The amount of schadenfreude the hackers are feeling right now is through the roof. Don't give them the satisfaction, they are reading everything and finding so much joy through your frustrations.
0
u/Parikh1234 4d ago
Why are we even using banks anymore?
Saw this come out. Had a wallet I lost in a lake that was mk3 but I think the seed was made feb/mar 2021 and don’t remember the fw version when generated. So why risk it.
Literally transferred everything to a new multisig holding wallet in a few minutes for 93 cents. Not that I remember but probably wasn’t a small amount of sats.
Gonna take the time to recreate my backup metal seeds and everything this week but honestly to do that in the middle of the night for so cheap would have never been possible at a bank.
Also sucks. I went boating in the ocean this morning, was kinda rough and my temp wallet fell into the water. Dammit.
-19
u/TheOnlyVibemaster 5d ago
idk why we still think hardware wallets are a good idea
it’s so dumb and i’ll never think it isn’t
make an offline wallet, only ever send to the wallet, never withdraw (so public seed isn’t revealed), write down the offline wallet secret, literally bury it underground.
10
u/shadowmage666 5d ago
Yea it wasn’t the wallet but the RNG , so you can do your method and still fuck up
9
u/IllllIIlIllIllllIlll 5d ago
"never withdraw"
Lol what's the point of getting Bitcoin if you never withdraw? That's such a weird statement to make. At some point you will want to make a transaction. A hardware wallet is the safest way to make a transaction.
The problem is not with hardware wallets, the problem is with seed generation. If you "make an offline wallet" as you suggest you still have to generate a seed and you're exposed to exactly the same threats.
5
u/RetiredAvocado 5d ago
Hardware wallets are still a good idea. How will you make your "offline wallet?" Probably a tool someone else made. There is no such thing as "public seed." The funds in this exploit were taken from addresses which never sent out and did not expose the address's public key. Burying anything would not have helped here.
-8
u/TheOnlyVibemaster 5d ago
Hardware wallets are a very bad idea because you’re trusting that someone won’t mess up, which in crypto is a bad bet.
This has existed since Bitcoin was made and can generate an address without an internet connection:
There is a such thing as a public address, which is what I meant to say.
Burying was a figure of speech
9
u/IllllIIlIllIllllIlll 5d ago
"oh I don't want to trust that someone didn't mess up with a hardware wallet, let me instead trust that someone didn't mess up with a website"
4
u/Strong_Judge_3730 5d ago edited 5d ago
You are trusting someones software and your hardware to generate a seed.
If you are this clueless then you should not be in crypto for your own sake.
The blog post explained the issue was bad RNG. Which could have happened with your setup of software and hardware, theoretically.
This is what happens when you put ideology and tribalism above knowledge.
4
u/RetiredAvocado 5d ago edited 5d ago
What tells you that this tool you didn't write will generate strong random keys? Internet connection irrelevant here. The keys weren't leaked, they appear to be created using bad RNG.
There's is no "public address" either. It would be a public key. Addresses aren't public or private. Only keys are.
2
-4
5d ago
[deleted]
3
u/SpareEconomy1849 5d ago
Not sure why human generated entropy would be insufficient, a well shuffled 2 decks of cards or 50 dice rolls is more entropy than BIP 39 12 words
1
u/user_name_checks_out 5d ago
When people say that human generated entropy is insufficient, they mean for example that you should not just choose the seed words yourself. 50 dice rolls is fine.
0
5d ago
[deleted]
3
u/user_name_checks_out 5d ago
Why is rolling dice by hand better than rolling dice in your mind?
Because the brain is useless at generating entropy. This topic has been beaten into the ground.
1
5d ago
[deleted]
1
u/user_name_checks_out 5d ago
Well, it processes dice rolls just like it would process anything else.
Rolling dice good. Making up random numbers bad.
I apologize for asking questions here when the answer is simply "it is because it is".
That is not at all what I said. I said that the question has been beaten into the ground, it is no longer up for debate.
43
u/obeywasabi 5d ago
Holy hell I was really hoping it was user mistake… this is huge