PSA: Iβm available for podcast appearances if anyone needs someone to explain of the problem, describe mitigations, or discuss entropy generation approaches. π #Bitcoin
In Bitcoin, ownership is what you KNOW. You either know the keys and can move coins, or you donβt.
So, how do you KNOW that nobody that you has your seed? The only way is to generate it yourself.
If you trust ANYONE ELSE to generate your seed material, then you DONβT KNOW that no one else has it.
Therefore, you MUST generate your OWN ENTROPY in order to KNOW that itβs safe. #Bitcoin
Your signing device has one job: to protect your seed material from leakage during use. The ColdCard has not failed in this.
People were trusting their ColdCards for an additional job: generating entropy. That was the mistake.
It does not help that wallet manufacturers encourage using the devices for entropy generation. #Bitcoin
View quoted note β
For people freaking out, here are a two relatively quick mitigations that donβt require any new hardware:
1. Using your existing ColdCard and seed, you can set up a passphrase. This acts like an entirely separate wallet on the same device. You can then sweep the coins to the passphrase sub-wallet.
2. Using your existing ColdCard and seed, set up a 2-of-2 wallet using that device and a software seed using Sparrow or Blue Wallet. Your attacker would have to both exploit the ColdCard vulnerability AND hack your software wallet to move those coins.
Stay frosty out there. #Bitcoin
If you roll the dice and put them in the machine to produce your seed, youβre STILL TRUSTING THE DEVICE.
How do you know that those dice rolls yield THAT seed?
Youβre out here thinking youβre paranoid using dice with a hardware wallet. Iβm telling you, you are NOT PARANOID ENOUGH. #Bitcoin