🪙
Coldcard flaw: weak RNG exposed 4,585 Bitcoin wallets to theft
🪙 Crypto

Coldcard flaw: weak RNG exposed 4,585 Bitcoin wallets to theft

A critical flaw in Coldcard hardware wallets caused some models to generate Bitcoin seeds using a weak software PRNG (MicroPython's Yasmarang) instead of the hardware entropy source from March 2021, reducing effective entropy to roughly 40 bits. Attackers drained 500 addresses before the cause was understood; Galaxy Research's count reached 4,585 compromised addresses. The bug sat in publicly readable firmware for over five years. The piece argues the incident illustrates why closed-source security is a false promise.

Comments

No comments yet