Coldcard RNG Flaw Exposes Bitcoin Wallets: Why Air-Gaps Fail Without True Entropy

Key Takeaways

A critical random-number-generation failure in Coldcard firmware reduces seed entropy, exposing wallets to brute-force attacks. Users must migrate funds to new seeds generated with fixed software or physical dice to ensure security.

Woofun AI reports that the fundamental assumption of air-gapped Bitcoin wallet security has been compromised by a newly disclosed random-number-generation failure within Coldcard firmware. This vulnerability demonstrates that a private key can remain exposed from the moment its seed is created, regardless of how long it stays offline. The contradiction is stark: a device designed to isolate cryptographic secrets from the internet can still produce seeds that are mathematically predictable, rendering the physical isolation meaningless if the initial entropy is insufficient.

The mechanism of this vulnerability lies in the predictable generation of the 12- or 24-word recovery phrase. Although these wallets store data in offline storage and perform isolated signing, the underlying seed generation process was flawed. An attacker does not need to breach the air gap; instead, they can reproduce candidate seeds elsewhere by exploiting the reduced randomness. By iterating through the limited search space, an attacker can identify matching Bitcoin addresses and drain funds, bypassing the offline security measures entirely.

The primacy of seed entropy over physical security measures becomes evident in this scenario. Security layers such as the PIN, steel backup, tamper-evident bag, and air-gapped signing flow are rendered ineffective if the initial seed lacks true unpredictability. A sound modern random-number generator is required to supply enough entropy to resist brute-force attacks. Alternatively, physical dice provide a source of randomness that is visible, controllable, and independent of the manufacturer's code, offering a more robust foundation for wallet security.

Coinkite’s entropy estimates for affected hardware models reveal the severity of the exposure. Preliminary data indicates that affected Mk2 and Mk3 seeds possess only roughly 40 bits of effective search space, while affected Mk4, Mk5, and Q seeds have approximately 72 bits. These figures represent the effective search space an attacker might explore. The drastic reduction in entropy means that the universe of possible seeds is small enough to be computationally feasible to crack, undermining the security guarantees provided by the hardware.

Woofun AI data shows, Block’s technical analysis of reseeding limits further clarifies the scope of the vulnerability for later devices. The analysis identifies a separate limit: at most 2^32 securely distinguished streams when the fallback state and call history were fixed. This narrower bound describes one part of the reseeding process under fixed conditions. It is important to note that this figure does not claim an end-to-end attack benchmark but rather highlights a specific constraint in the entropy accumulation process that could be exploited.

Mitigation strategies focus on firmware updates and seed migration to secure existing funds. Updating to a fixed release protects future seed generation, but an existing seed retains the entropy it received at birth. Every address derived from that seed shares the same root secret, meaning the vulnerability persists across all derived keys. Users who used an affected version should check the advisory and create an entirely new seed with fixed software and trustworthy entropy. If the private-dice exception cannot be established, migration is essential. Funds must move to the new wallet, as a new address from the old mnemonic preserves the weakness.

The dual shock of theft risks and rational fund migration creates significant market dynamics. On-chain data records the movement of funds as users react to the advisory. The motive for migration requires context: the checksum detects errors while contributing zero new unpredictability. Hashing or formatting weak input into longer output preserves the underlying ceiling on possible secrets. Consequently, twelve familiar-looking words can represent a tiny subset of the space they appear to offer, making rational migration the only viable defense against potential theft.

Proper implementation of physical dice for entropy is critical for those seeking an alternative to device-generated randomness. Physical rolls help only when the wallet's documented procedure incorporates them correctly. The die must be suitable for the task, each roll must be genuine and independent, and the sequence must stay private. Reused patterns, photographs, cloud notes, and entry on a networked computer can undermine the rolls' independence or secrecy. For this Coldcard incident, Coinkite says migration may be unnecessary only when the user can establish that the final seed incorporated at least 50 fair, independent and private dice rolls. Its advice for uncertainty is migration.

Trust chains, dice math, and alternative security layers offer additional perspectives on wallet security. Device-generated randomness asks the owner to trust the hardware, firmware, build process, and integration code as one chain. A documented dice-entry flow adds owner-controlled entropy from outside that chain. Roughly 50 fair rolls target 128 bits and 99 target about 256 bits, but users should follow the device's exact procedure instead of improvising a conversion. A strong, unique BIP-39 passphrase changes the attack in a different way by adding an independent secret.

However, every passphrase, including a typo, derives a valid-looking wallet, so loss of the exact passphrase can strand the intended funds. A device PIN serves a different purpose, acting as a second barrier, but poor backup can lock oneself out.

Historical precedents, financial impact, and final verdict underscore the importance of true entropy. Researchers found more than 2,600 actively used Bitcoin wallets in the affected ranges and estimated more than $900,000 in related theft across multiple chains at August 2023 prices. More than 2,550 of those wallets shared an automated pattern and may have belonged to one owner, and the researchers said some drains could have involved other weaknesses. The implementations differed: an accidental firmware fallback, a browser-extension Wasm path, and a time-seeded command-line tool. Each produced output that looked like a full-strength wallet secret while exploring only a fraction of the apparent space. An air gap protects the secret you give it, but the randomness has to come first.

Vote

Will Coldcard's RNG flaw expose wallet private keys?

0 people voted

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions