
Today it appears that the entropy (or lack thereof) behind Cold Card seed generation was exploited.
The tl;dr is that bad randomness in Mk3 seed generation for Cold Card hardware wallets led cluster of roughly 594 BTC being swept from about 500 addresses in a short window.
Coinkite warns that seeds generated on Mk3 firmware 4.0.1 through 5.0.3 may be at risk. However there's evidence that Mk4, Q, and Mk5 could also be affected, though would require much more compute.
The proposed mechanism is:
1. The Mk3’s seed-generation path produced insufficiently unpredictable entropy for some setups.
2. Instead of a truly 128/256-bit secret, the output may have been drawn from a much smaller or structured state space.
3. An attacker can reproduce the candidate seeds offline, derive standard BIP-32/BIP-44 address paths, and scan the blockchain for funded matches.
4. Once a candidate matches a known address, the attacker has the corresponding private key and can sweep it. The device PIN, air gap, and secure element do not help at that point.
no reason to believe that Ledger, GridPlus, or Trezor devices share similar shortcomings, but this DOES highlight something: trust is everywhere in crypto. We want things to be trustless, but you have to trust that:
- your exchange won't ban you
- your wallet software won't act maliciously
- your hardware wallet firmware won't export your private keys to the feds
- your seed is generated with sufficient entropy
It seems like nothing is safe.
At this point I have to recommend multi-device multisigs for anything of significant value to you.
Generate at least two seeds using at least two different vendors (say GridPlus and Ledger) and then configure a multisig using wallets from each seed.
Write the seeds only on paper, split them via shamir secret sharing and distribute them geographically, among family etc.
Or just give up the dream and buy crypto ETFs.






評論與回覆
暫無評論