source avatarTFTC

Share

.@KLoaec from Wizard Sardine just published a full technical breakdown of a critical Coldcard vulnerability. Every seed generated on the device since 2021 is compromised. Wallets are being drained right now. The chip has a perfectly working hardware random number generator. Nobody was calling it. "The Coldcard replaces MicroPython's randomness module with its own, deemed more conservative. To do so, it disables the original one... The catch is that MicroPython does not remove rng_get() when that flag is 0. It replaces it with a software imitation." The result: "a Coldcard seed no longer held a single bit of physical randomness." A compile-time safety check should have caught this but used `ifndef` instead of `if`. "One character stood between that safeguard and its purpose." It passed on every build for 5+ years. Seeds from 50+ dice rolls or pre-2021 are safe. Everyone else: move funds now. https://t.co/NrQweAB3yy

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.