A firmware bug in Coinkite's Coldcard wallet generated seeds with too little randomness, and attackers reconstructed the keys and took roughly 600 bitcoin. The company's advice now is to move funds to a new seed, generated properly, and to add dice rolls for entropy. Removing trust from the ledger was never the hard part. Generating a random number correctly, every time, on hardware you didn't build yourself, was always going to be someone's weak point. The incentive to skip that step quietly favors whoever controls the firmware, not the holder.
0 replies
No replies yet.