No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it was

NewsMon, 03 Aug 2026 12:39:13 UTC6 hours ago
No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it was

Most people don't realize that an air-gapped Bitcoin wallet can keep a private key away from the internet for years and still be vulnerable from the moment its seed was created.

Coldcard’s newly disclosed random-number bug highlights the trap well. An affected wallet could hand you a perfectly ordinary 12- or 24-word recovery phrase, then let you lock it away and sign transactions offline. Underneath, the generator was dealing from a much smaller deck. An attacker could run through that deck on another machine and rebuild likely seeds. Bitcoin’s public ledger would show which guesses matched real addresses.

For me, a wallet’s fate is decided at the point of creation. Before the PIN, steel backup, tamper-evident bag or air gap can help, the seed has to begin with real randomness.

A sound modern random-number generator can supply enough entropy. However, if a bad actor knows the process by which the RNG was created it can be possible to backwards engineer the process.

A physical dice roll gives the owner a source of randomness that can be seen, controlled, and kept separate from the manufacturer's code.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related