Do the Coldcard attacks mean all hardware wallets are now insecure?
The Coldcard entropy flaw caused a crisis of confidence in hardware wallets. Here’s the details you need to know before you entrust Ledger, Trezor or Foundation with your Bitcoin.
The discovery of a flaw in the Coldcard hardware wallet has raised concerns about the security of other hardware wallets on the market. The flaw, which was uncovered on July 31, affects multiple Coldcard devices and has allowed attackers to steal over 1,596 Bitcoin, worth at least $100 million, through coordinated attacks. This incident has prompted a reevaluation of the security of all hardware wallets, including those from popular manufacturers such as Ledger, Trezor, and Foundation.
Hardware wallets are designed to securely generate private keys to protect users' Bitcoin. The security of these wallets relies heavily on the randomness generated during the seed phrase creation process. However, the Coldcard flaw exposed a weakness in the entropy-generation process, which could potentially weaken the randomness and make the resulting private keys more vulnerable to attacks.
Coinkite, the company behind Coldcard, has released firmware fixes and advised affected users to migrate their funds to newly generated wallets. Yet, the incident has shaken the confidence of Bitcoin holders and highlighted a fundamental issue: the importance of randomness in securing private keys. Weak random number generation is not a new problem, and Bitcoin security experts have identified various instances of compromised RNG in cryptocurrency wallets and libraries.
Despite the vulnerability in Coldcard, the industry's leading hardware wallet manufacturers have responded by emphasizing the importance of secure entropy generation. Ledger, Trezor, and Foundation all employ different strategies to ensure the randomness of their devices' seed generation processes. Ledger focuses on using a true random number generator embedded in a certified Secure Element, while Trezor combines randomness generated inside the device with randomness supplied by the host computer.
Foundation's Passport wallet relies on multiple entropy sources and has an open-source firmware that can be independently verified by researchers.
The Coldcard incident underscores the need for hardware wallet manufacturers to prioritize secure entropy generation and maintain transparency in their processes. As long as the randomness used to generate private keys remains unpredictable, hardware wallets can continue to provide a robust and secure method for self-custody of Bitcoin.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.