🔒 Coldcard bug: weak seeds generated since 2021, Coinkite urges users to move funds immediately Less than 24 hours after a 594 BTC theft, Coinkite published a security advisory confirming a flaw in seed generation across multiple Coldcard models. Seeds generated on Mk3 running firmware 4.0.1 (March 2021) or later have an estimated effective search space of only around 40 bits, making key recomputation a feasible industrial-scale operation. Mk4, Mk5 and Q models are also affected, producing seeds with approximately 72 bits of entropy instead of the expected 128, prior to corrective firmware releases (5.6.0 for Mk4/Mk5, 1.5.0Q for Q). Coinkite warns all affected users that "funds may be at risk" and advises moving them immediately. Tapsigner, Opendime and Satscard are not affected, as they run on different codebases. The advisory does not explicitly link the vulnerability to the 30 July theft, though the timeline is notable: Coinkite CEO NVK stated hours before the advisory that there was "no evidence of a flaw" in the device's random number generator. According to Coinkite's technical review, the bug was introduced during a 2021 migration to libsecp256k1, with the hardware entropy source effectively cut out in the process. As the company acknowledges: "The cryptographic choice was sound. The integration was not." https://t.co/5ap9wxt53y
Atlas21Share

Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.