Bullish
COLDCARD Wallet Seed Randomness Reduced Since 2021 Due to RNG Error
2026-07-31 18:39:07
Coinkite confirms COLDCARD wallets generated with weaker software RNG since March 2021, making seeds easier to guess. Mk3 devices most affected; build process updated.
Woofun AI reports that Coinkite identified a vulnerability in COLDCARD wallet seed generation dating back to March 2021. During the libNgU migration, the device utilized a weaker software random number generator instead of the hardware-specific unit, reducing entropy for certain Bitcoin wallets. Mk3 devices are primarily impacted, while Mk4, Q, and Mk5 models include additional hardware randomness but still use the same software component. The error stemmed from a naming conflict between two software functions during the build process, which has since been corrected.
WOOFUN AI
Impact Assessment · Quick Read
This disclosure highlights critical risks in hardware wallet supply chains, where software build errors can compromise cryptographic security despite robust hardware designs. Users with Mk3 devices generated after March 2021 face elevated theft risks if seeds were not properly backed up or if the weaker RNG was exploited. The incident may drive broader scrutiny of open-source wallet audits and reinforce demand for wallets with verifiable, hardware-only entropy sources.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.