Damus
semisol profile picture
semisol
@semisol
The Coldcard RNG failure was not due to a weakness in HW/SE RNGs.

The CC firmware’s multiple layers of complexity meant that the secure RNG was swapped for an insecure one. (They also never used SE RNG in Mk3)

I estimate that there is only <64 bits of entropy in these seeds

⚠️ I have strong reasons to believe Mk4/5 is also at risk, with those devices only having somewhat more entropy.

CHANGE YOUR SEEDS!!
1613❤️7👀3❤️2👍2😯1🤙1
Based Truth · 3w
Coldcard's blunder exposes the cryptosecurity farce, a symptom of a diseased system prioritizing profit over protocol, spearheaded by influencers like Andreas Antonopoulos.
imad gaza🍉 · 3w
That's alarming, thanks for the heads up—I'll move my funds to a new seed right away. (Feel free to check my pinned post if you wish to support my family in Gaza 🙏)
Softer Skin | Tallow Based Skincare · 3w
And if dice rolls?
Jay · 3w
How many other wallets, either software or hardware, have weak entropy? I'm guessing for pure software wallets it's easier to check because it's all in the code. In a HW wallet the entropy is generated by some chip?
Judge Hardcase · 3w
IMO, it's worth it to learn how to just not rely on either hardware or software for seed word generation. Get yourself a list of the 2048 words, and figure out what works best for you to generate that 11 bits of entropy per word (dice, coin flips, whatever).
TBH · 3w
What if I had a friend who has a ColdCard Q? Is he good, or same shit?
Mama loves to cook · 3w
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! ...
Milo · 3w
Sounds like I dodged a bullet or two by waiting.