MultiversX Tracker is Live!

ColdCard users lost ~1,367 BTC (~$89M) because a 2021 firmware bug silently swapped hardware RNG for a software one — the case for multi-source, fail-closed entropy

Bitcoin Reddit

More / Bitcoin Reddit 20 Views

Verification because this sounds unreal: Privacy Guides and The Hacker News both covered it at the start of August 2026 — attackers drained thousands of ColdCard wallets for a total of ~1,367 BTC (~$89M). Root cause: a firmware bug from 2021. During seed generation some devices silently fell back from the hardware RNG to a weak software RNG. The 24-word seeds looked completely normal — no warnings, nothing. But they could be reconstructed offline, years later.

The scary part is that weak randomness looks identical to good randomness, right up until someone else derives your keys. ColdCard's incident was a trust failure: a single chain of trust ("one certified chip from a trusted vendor") that had a silent fallback path. It's now the clearest proof that one point of trust in entropy is one point of failure.

This is why I now look at entropy architecture differently:

  1. Certified chip ≠ failure-proof design. A certified secure element is a vendor claim, not a guarantee. If the firmware around it can silently fall back, the certification is worthless exactly when it matters.

  2. Multi-source matters. Two independent chips from two manufacturers (STM32 TRNG + NIST SP 800-90B certified ATECC608C) each harvest separate physical noise. Compromising one does not compromise the seed — because the SHA-256 blend cannot be reversed. One honest source in the mix keeps the output unpredictable.

  3. Fail-closed is the property that matters. Some wallets now run on-device statistical randomness tests on every entropy input. A lazy swipe, a camera pointing at a table, an idle device — the input is rejected and the step repeats. The device refuses to continue rather than accept bad entropy. That is exactly the property ColdCard's 2021 fallback violated.

  4. User-entropy input (camera, screen drawing, device shake) kills the "factory deck" problem. No manufacturer could have precomputed your room and your motion at that moment.

What I still want before trusting large amounts (honest concerns): - Firmware transparency: third-party audits, reproducible builds, published entropy logs. A paper describing the pipeline is not the pipeline. - Some wallets only mix user entropy in an "expert flow"; the standard flow still relies on the two hardware chips. Those are solid, but a user decision shouldn't change the security floor. - Side-channel and fault attacks still exist — more sources reduce risk, nothing is absolute.

The bar I'll use after this incident for any hardware wallet I recommend: "Can this device fail closed — refuse loudly when entropy is weak — or does it silently continue?" ColdCard silently continued. Everything else is marketing.

submitted by /u/CommercialMonth3640
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments