benma

1.5K posts

benma banner
benma

benma

@_benma_

works @BitBoxSwiss / BitBox02, #bitcoin

Katılım Temmuz 2018
160 Takip Edilen1.2K Takipçiler
benma
benma@_benma_·
@AdamSimecka @ManThatCrazy AIs uncover the bug it in minutes. They used that and/or they got the details from others who used it.
English
0
0
1
45
Adam Simecka
Adam Simecka@AdamSimecka·
@ManThatCrazy You're missing my point. How did coinkite know the missing funds were due to rng bug so quickly, when the exploit had been there for 5 years?
English
8
0
14
1.7K
Adam Simecka
Adam Simecka@AdamSimecka·
So, no one knew about the RNG bug for 5 years, but then in one afternoon, it took them like an hour to find it? Something isn't adding up.
English
103
35
546
42K
benma
benma@_benma_·
@LLFOURN @slush I meant combining actual 32 byte entropy sources, not timestamps and the like.
English
0
0
0
78
slush
slush@slush·
Trezor is mixing entropy from several sources since early prototypes in 2013, to prevent exactly what's happening now to some hw wallets (and what happen before to some software wallets, too). 👇
Tomas Susanka@tsusanka

Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.

English
15
40
459
110K
benma
benma@_benma_·
@LLFOURN @slush It was a problem. They primarily relied on the one TRNG and it failed. If they had mixed in other good sources, this problem would have been sufficiently mitigated.
English
1
0
5
257
Zero-Knowledge Goof
@slush This post doesn't make sense. The number of sources of entropy wasn't a problem. CC used several. The problem is that it didn't use the one that mattered: the hardware TRNG.
English
3
1
21
3K
benma
benma@_benma_·
Don't forget to move the funds in your wallets which are backed by BIP-85 seeds derived from Coldcard.
English
0
3
13
975
Grease
Grease@LowTimePrefrenz·
@_benma_ What if multisig 2/3 with autogenerated 24 word seeds from Mk4s?
English
1
0
1
166
benma
benma@_benma_·
Multisig accounts where affected coldcards make up the signing threshold (e.g. 2-of-3 are affected coldcards) are also potentially vulnerable for addresses that were reused (or where the descriptor is known). I recommend moving these funds too in abundance of caution.
English
2
0
20
3.6K
ODELL
ODELL@ODELLXYZ·
developing situation, but if you are currently using coldcard move your funds out of an abundance of caution bugs have been found and exploited using ai if you used dice rolls to generate your seed, you should be fine if you use a passphrase, you should be fine if you use multisig, you should be fine would still move funds out of an abundance of caution this sucks, coinkite team should release more info soon
English
105
142
1K
74K
benma
benma@_benma_·
@KLoaec Indeed, one past spend is enough :o thanks!
English
0
0
2
175
Kevin Loaec 🧙‍♂️🐟
@_benma_ Attacker could easily make a table of keys, scan past txs containing them (including multisig) and from there know if it's only MK3 and generate the descriptor. It requires only one past spend from the wallet, no need for address reuse not descriptor.
English
1
0
8
325
benma
benma@_benma_·
@KLoaec Let's say the search space of one seed is 2^32. Single sig unsafe, multisig with three keys search space would grow to 2^96, so not feasible? If pubkeys are known (e.g. via addr reuse), it's just a constant factor increase.
English
1
0
4
455
Kevin Loaec 🧙‍♂️🐟
@_benma_ Descriptor does not need to be known. If all keys are MK3, the attacker can easily detect them on chain and reproduce the descriptor. If only the threshold is MK3, the attacker can double spend while in the mempool.
English
3
3
18
2.1K
Kevin Loaec 🧙‍♂️🐟
@deathcab Not sure I get your point. No matter the number of keys or threshold, if it's only MK3s being used, FUNDS ARE AT IMMEDIATE RISK It is trivial to exploit.
English
3
0
6
1.5K
Kevin Loaec 🧙‍♂️🐟
I had the question multiple times: if you have a MULTISIG consisting ONLY OF MK3, you are AT RISK. This is not a single sig issue only.
English
14
29
178
33.1K
benma
benma@_benma_·
@heavilyarmedc In any case your premise is wrong, a typical user affected by a bad HWW bug that produces bad seeds does not imply the user has a very weak passphrase.
English
1
0
2
31
benma
benma@_benma_·
@heavilyarmedc If you have a small search space to brute force the seed, without passphrases it finishes quickly. If for every brute force attempt you also had to brute force passphrases, it makes it much harder. Just covering 4 chars makes it ~15million times slower, which is a lot slower.
English
1
0
2
33
Heavily Armed Clown
Heavily Armed Clown@heavilyarmedc·
on this silly reddit thread... Passphrases will not save you from insufficient entropy on your seed unless the passphrase itself has sufficient entropy. I highly doubt someone incapable of using sufficient entropy for their seed is going to somehow use a secure passphrase.
Heavily Armed Clown tweet media
English
4
1
28
2.7K
benma retweetledi
Nick Neuman
Nick Neuman@Nneuman·
It sounds like Mk4, Q, and Mk5 are also vulnerable in a different way than Mk3. Slightly less problematic than Mk3 but still not great to keep using. If you're using single sig Coldcard at the moment you should move your assets to a different wallet (multisig, exchange, other HWW) to be safe.
English
16
35
173
21.4K
benma retweetledi
instagibbs
instagibbs@theinstagibbs·
Confirmed. Mk2/3 vuln, I don't think mk4 is but can't be certain
instagibbs tweet media
English
39
91
535
344.9K
benma retweetledi
James O'Beirne
James O'Beirne@jamesob·
If you have bitcoin residing under a single key that was generated on a Coldcard Mk3 between 2021-2023, and you - did not incorporate dice rolls - do not use a passphrase - do not use multi-sig I would advise moving funds as soon as possible.
English
125
407
1.7K
490.8K
benma retweetledi