No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it was

1 hour ago 1



Most people don't realize that an air-gapped Bitcoin wallet can keep a private key away from the internet for years and still be vulnerable from the moment its seed was created.Coldcard's newly disclosed random-number-generation failure makes the contradiction plain. A wallet running affected firmware could produce a normal-looking 12- or 24-word recovery phrase, store it offline, and sign transactions in isolation. Predictable generation shrank the universe behind those words, allowing an attacker to reproduce candidates somewhere else and identify matching Bitcoin addresses.I see a wallet's most consequential security decision at the beginning. It comes before the PIN, the steel backup, the tamper-evident bag and the air-gapped signing flow: how unpredictable was the seed?A sound modern random-number generator can supply enough entropy. Physical dice give the owner a source of randomness that can be seen, controlled and kept separate from the manufacturer's code.The seed was weak before the wallet went offlineCryptoSlate's first report on the Coldcard flaw explained the attack path. Candidate seeds can be generated away from the device, converted into public addresses and checked...

Read Entire Article