I'm not invested into cryptocurrencies but I'm fascinated by the cryptography behind it.
I read a bit about it and the source of this bug is a bit crazy if you think about what the job of a hardware wallet is supposed to be: AIUI an error made it so that when the secure random number generator in the hardware wallet couldn't not be used, Coldcard would fallback to a low-entropy software RNG.
It's a bit of a "you had ONE job" thing. But no, they somehow managed to screw up by using a system that, instead of failing should using the secure RNG be unavailable, would silently fall back to an insecure RNG.
And you kinda have to feel a bit bad for these guys because it's apparently, and in a very ironic way, one of the only hardware wallet that allows to easily use dice to add entropy to the seed (using dice on your own ain't easy for those seeds do have a checksum that must be computer in a secure way and, for example, computing it on an online computer totally defeats the purpose of hardware wallets with secure elements).
So in a way Coldcard failed because they made the "dice for added entropy" functionality optional instead of mandatory. Had they made it mandatory, even their royal screwup with the fallback to an insecure RNG wouldn't have compromised their users' seeds.
I'm not invested into cryptocurrencies but I'm fascinated by the cryptography behind it.
I read a bit about it and the source of this bug is a bit crazy if you think about what the job of a hardware wallet is supposed to be: AIUI an error made it so that when the secure random number generator in the hardware wallet couldn't not be used, Coldcard would fallback to a low-entropy software RNG.
It's a bit of a "you had ONE job" thing. But no, they somehow managed to screw up by using a system that, instead of failing should using the secure RNG be unavailable, would silently fall back to an insecure RNG.
And you kinda have to feel a bit bad for these guys because it's apparently, and in a very ironic way, one of the only hardware wallet that allows to easily use dice to add entropy to the seed (using dice on your own ain't easy for those seeds do have a checksum that must be computer in a secure way and, for example, computing it on an online computer totally defeats the purpose of hardware wallets with secure elements).
So in a way Coldcard failed because they made the "dice for added entropy" functionality optional instead of mandatory. Had they made it mandatory, even their royal screwup with the fallback to an insecure RNG wouldn't have compromised their users' seeds.
So $70 million was sitting in open for 5 years, until someone picked it up. Crypto is the ultimate self-funding bug bounty.