Updated:10:41 AM CEST Aug,04
(new)
(c) 1998-2026 Gameguru Mania
Privacy Policy statement
|
How the Coldcard Bug Was Born and Exploited - gameguru review|
| (hx) 10:00 AM CEST - Aug,04 2026 |
The case of ColdCard wallet worked because the implementation was broken (radically reduced entropy). It wasn't the cryptography that failed, it was a software engineering bug Brute-force remains mathematically impossible
In 2020, after a competing device used Coldcard's then-GPL code, Coinkite switched to a more restrictive MIT + Commons Clause license. On March 1, 2021, a large “First pass w/ libNgU” commit removed remaining GPL code and, in the process, disabled the hardware random number generator.
Firmware fell back to a weak software RNG (Yasmarang), sharply reducing entropy for new wallet seeds on affected devices. The flaw remained undetected for years until attackers began sweeping vulnerable addresses in late July 2026, moving well over 1,000 BTC....read a full article |
|
last 10 comments:
|
|