Listen to the article
The risk, which remains until users take action, is confined to specific devices and firmware. Owners of the Mk3, Coldcard’s 2019 model, should move their funds now if the wallet was set up on firmware 4.0.1 or later. Mk4, Mk5 and Q owners on firmware below 5.6.0 or 1.5.0Q should update, create a new wallet and then move their coins across.
Coinkite has said the exception is anyone who used the device’s dice option, where a user physically rolls dice at least 50 times and types in the results, and the wallet builds its key from those numbers instead of generating its own. Those wallets never touched the broken code and are safe.
A seed is the master key controlling a wallet’s coins, so one produced with too little randomness, or entropy, can be guessed and regenerated by an attacker, who can then drain the wallet without ever touching the device.
Vincent Bouzon, director of product security at Ledger, which makes competing hardware wallets, said the incident was a failure of one implementation rather than a verdict on self-custody.
“Every wallet ultimately depends on a root secret generated from high-quality entropy,” Bouzon told CoinDesk in an email, adding that the generation of that entropy “must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”
Read the full article here
Fact Checker
Verify the accuracy of this article using AI-powered analysis and real-time sources.

