Bitcoiners turn to dice throws as self-custody setups are re-evaluated
Dice entropy may become the new gold standard after the Coldcard hack
Following the Coldcard hardware wallet hack, which revealed a critical flaw in its low-entropy seed generation process, Bitcoin holders have begun to reassess their self-custody setups. Coldcard devices were equipped with STM32 true random number generators (TRNGs) intended to create unguessable seed phrases, but after the firmware rewrite in March 2021, a vulnerability was introduced.
This vulnerability stemmed from the use of MicroPython's Yasmarang PRNG instead of the STM32 hardware RNG, which analysts described as a pre-programmed fallback.
Coinkite recently disputed the characterization of the Yasmarang PRNG as an insecure method of seed generation, sparking speculation on X about whether this was a deliberately placed backdoor. Analysts have speculated that the bug may have stemmed from careless development practices aimed at suppressing errors through random changes. Both Mk2 and Mk3 devices generated seeds with 40 bits of entropy, while Mk4, Mk5, and Q devices achieved around 70 bits, which are insufficient for a secure 12-word seed phrase.
Since the vulnerability's discovery, attackers have been successfully brute-forcing private keys, resulting in over $100 million worth of BTC being stolen. To mitigate this risk, some users have resorted to adding dice entropy or utilizing BIP-39 passphrases and non-standard paths. In response to the incident, James O’Beirne set up a website called cktripwire to track which types of wallets attackers are targeting.
The Coldcard exploit has once again emphasized the community's core principle of "Don’t trust, verify," as users who did not rely on opaque engineering to generate entropy for their security-critical components avoided the exploit.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written; read the original for the full account.

