₿ BTC PodsBe a Pod Maxi
← Guests

Guest

James O'Beirne

TFTC: A Bitcoin Podcast

777: Coldcard Is Compromised with James O'Beirne

- Coldcard RNG vulnerability: Devices produced after 2021 (MK2, MK3, MK4, Q models) contain an insufficient random number generator that limits entropy to ~70 bits instead of the required 256 bits, making private keys vulnerable to brute-force attacks. - Migration urgency by device and setup: Single-signature users without dice rolls or strong passphrases on post-2021 devices must move funds immediately; multisig scenarios are more complex and depend on whether public keys have been revealed on-chain. - Safe mitigations: Users who performed 99+ dice rolls during key generation or use a sufficiently complex passphrase (substantially longer than six BIP39 words) are protected and do not need to migrate. - AI acceleration of vulnerability discovery: Language models like Claude 3 independently reproduced and identified the vulnerability within hours, demonstrating how advanced AI tools lower the barrier to finding security flaws in open-source projects. - Multisig complexity: In multisig setups, vulnerability depends on whether all signing keys are from Coinkey products and whether their public keys have been exposed on-chain; if any non-Coinkey device is required to spend, the setup remains secure. - Broader hardware wallet trust collapse: This event underscores systemic risks in single-vendor solutions and reinforces the need for multi-manufacturer, multi-signature custody with user-supplied entropy sources.