Coldcard Releases Security Update, but Affected Seeds Need Replacing

1 month ago 8

Rommie Analytics

Key Takeaways

  • Mk4/Mk5 5.6.1 and Coldcard Q 1.5.1Q are the current standard releases.
  • Check the firmware used when the seed was created.
  • The dice exception requires 50 private, independent rolls.
  • New seeds require user-generated randomness.
  • Outside reviews checked specific fixes, not every firmware risk.

Why a device update is not enough

Coinkite released the current firmware after a seed-generation defect was connected to reported Bitcoin thefts. The incident did not involve an attacker remotely unlocking every Coldcard device. It involved the way certain recovery seeds were created.

During a 2021 code migration, seed generation reached a software pseudo-random-number generator instead of Coldcard’s intended hardware random-number generator. The result was insufficient randomness in some seeds. Coldcard estimates that affected Mk2 and Mk3 seeds may have had an effective search space of about 40 bits; later Mk4, Mk5 and Q models received extra entropy from secure elements, raising the preliminary estimate to a...

Read Entire Article