A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button

Some Coldcard Mk3 owners may need to move their Bitcoin. Coinkite says funds tied to seeds generated on firmware 4.0.1 or a later Mk3 release may be at risk.
Bitcoin Core contributor instagibbs said he recreated the vulnerable seed on a newly initialized Mk3. Coinkite says Mk4 and Mk5 devices are also affected before firmware 5.6.0, while Q devices are affected before 1.5.0Q; the impact is less severe but still serious. The company plans a formal technical review of the root cause.
A hardware wallet protects an existing key through secure storage, offline signing, and on-device verification. Seed generation precedes those defenses and determines whether the device starts with strong key material.
A seed phrase draws security from entropy, the randomness that selects one combination from an immense field. Weak randomness narrows that field until an attacker can test candidate seeds, derive their addresses, and watch for deposits from another computer.
Predictable creation defeats the air gap at the starting point and turns theft into a remote search problem. An attacker can work from candidate seeds, monitor the corresponding addresses, and spend the funds once a match appears.
โฆ Continue reading the full article at the original source below.


