A flaw in the Coldcard hardware wallet’s entropy generation process has resulted in a coordinated attack, allegedly stealing over $100 million worth of Bitcoin.
The vulnerability stemmed from a reliance on a weaker random number generator within the device’s firmware. Following the disclosure by Coinkite on July 31, 2023, attackers successfully exploited this weakness to generate multiple keys and reproduce them. This targeted randomness, rather than undermining core cryptographic principles.
According to reports, more than 1,596 Bitcoins were potentially affected through coordinated attacks that began shortly after the initial disclosure. Michael Tanguma, Head of Product at Onramp Bitcoin, highlighted a key element of the situation: “The whole model rests on trust that the vendor got it right…Almost no individual can audit the hardware, the firmware and the entropy generation underneath their device.”
Researchers at Galaxy Digital subsequently confirmed the scale of the theft. The bug itself was discovered in 2021 when code intended to interface with the hardware random number generator instead disabled its function, according to a theory suggested by Dustin Dettmer, Core Lightning Developer. Jameson Lopp, a noted Bitcoin security expert, previously highlighted similar vulnerabilities in wallets like Blockchain.com’s Android wallet and Trust Wallet.
Several manufacturers have responded. Vincent Bouzon, Director of Product Security at Ledger, explained the company’s approach utilizes certified Secure Elements for secure entropy generation. Tomáš Sušánka, Chief Technical Officer at Trezor, emphasized the importance of avoiding reliance on a single source or line of code for randomness and Zach Herbert, CEO of Foundation (developer of the Passport wallet), highlighted their use of multiple hardware components and open-source development.
Kraken’s Chief Security Officer, Nick Percoco, described the incident as a “wake-up call” for the entire hardware wallet industry. He proposed the need for stronger industry standards around assurance. Independent certification offers some reassurance, but doesn’t guarantee accurate firmware use, according to Vincent Bouzon of Ledger.
The weakness highlighted by the Coldcard incident extends beyond this specific device; it underscores a wider concern about entropy generation across the hardware wallet ecosystem and its reliance on vendor trust. Five years elapsed between the bug’s creation and detection, raising questions about oversight within the industry.
Written by Daniel Brooks
Security Desk