7OrStone

Market Prices

BTC Bitcoin
$77,661.4 +0.88%
ETH Ethereum
$2,460.19 +1.89%
SOL Solana
$95.49 +1.79%
BNB BNB Chain
$703.3 +1.03%
XRP XRP Ledger
$1.52 +3.08%
DOGE Dogecoin
$0.0930 +0.87%
ADA Cardano
$0.2261 -0.35%
AVAX Avalanche
$7.64 +1.61%
DOT Polkadot
$0.9291 +0.87%
LINK Chainlink
$11.57 -0.01%

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,661.4
1
Ethereum ETH
$2,460.19
1
Solana SOL
$95.49
1
BNB Chain BNB
$703.3
1
XRP Ledger XRP
$1.52
1
Dogecoin DOGE
$0.0930
1
Cardano ADA
$0.2261
1
Avalanche AVAX
$7.64
1
Polkadot DOT
$0.9291
1
Chainlink LINK
$11.57

🐋 Whale Tracker

🔴
0xa5f2...27ef
30m ago
Out
1,205 ETH
🔵
0x0d46...d3a0
30m ago
Stake
4,966.97 BTC
🟢
0xa5f2...4b80
1h ago
In
2,751 ETH

Coldcard's RNG Catastrophe: How a Flag Zero Became a Million-Dollar Problem

Business | Hasutoshi |
On August 20th, 2024, Coinkite published a security advisory that would reshape how the industry thinks about hardware wallet entropy. The advisory acknowledged a critical flaw in the random number generator implementation across multiple Coldcard firmware versions. Block's independent technical analysis, released two days later, traced the defect to a single logical error: a feature flag defined as zero was being interpreted as "flag exists." The consequences of this architectural oversight remain under investigation, but the ledger remembers what the promoters forgot. Coldcard has occupied a privileged position in Bitcoin's self-custody ecosystem for over a decade. Founded in 2013, Coinkite built its reputation on air-gapped signing, open-source firmware, and what users perceived as paranoid attention to cryptographic detail. The Mk4 and Mk5 devices became favorites among Bitcoin maximalists who dismissed Ledger's multi-chain approach as feature creep and viewed Trezor's accessibility as a liability. This incident punctures that narrative of technological purism. The technical core of the vulnerability lies in how the firmware handled the RNG path selection during seed generation. Block's analysis identified that code routing requests to a deterministic MicroPython fallback occurred because "feature flags set to zero were evaluated as if they existed." In practical terms, the device could, under specific conditions, generate seeds using predictable entropy sources rather than true random sampling from the hardware RNG. The attack surface was narrow but severe: an attacker who identified the triggering condition could potentially derive the resulting seed through brute force computation. Coinkite's remediation strategy introduces mandatory manual entropy input for new seed generation. Mk4 and Mk5 users must perform 50 dice rolls or 128 coin flips, pressing physical buttons to capture each outcome. The Q variant requires 65 total inputs. This approach represents a fundamental shift in the trust model. Where previous firmware implicitly trusted the hardware RNG, the patched version treats user-generated physical randomness as the only reliable entropy source. The hardware RNG is now auditioned rather than assumed. I have spent the better part of two decades dissecting cryptographic failures across this industry. The pattern here is instructive. Deterministic fallbacks exist in nearly every production cryptographic system because engineers require escape routes when entropy sources fail. The problem emerges when those fallback conditions become reachable through non-obvious code paths. Coldcard's flaw was not that they implemented a deterministic fallback. The flaw was that the configuration logic activated the fallback when it should have remained dormant. The migration requirements for existing users present their own category of risk. Coinkite has explicitly stated that the new firmware cannot retroactively add entropy to seeds generated under vulnerable versions. Every affected user must generate a fresh seed on a patched device, transfer all funds, and verify the destination addresses. For users holding large portfolios across multiple seed phrases, this process introduces operational complexity that itself becomes a threat vector. Phishing sites mimicking migration guides have already appeared. Malware designed to intercept the seed generation process during the user's distraction is a reasonable expectation. Block's analysis extended further than Coinkite's own disclosure in at least one significant dimension. The third-party audit identified potential vulnerability in firmware versions Coinkite had not listed in their initial advisory. This raises uncomfortable questions about the manufacturer's own testing protocols. An entropy pathway vulnerability of this severity should have been caught by systematic fault injection testing. The absence of such detection suggests either the test suite lacked coverage or the defect had existed long enough to evade whatever validation existed before release. The counter-intuitive dimension of this incident deserves examination. Coldcard's "paranoia" positioning may have created blind spots in their security review. When a brand markets itself as the choice of extreme security practitioners, internal review teams may unconsciously deprioritize vulnerabilities that seem implausible. Meanwhile, less security-focused competitors might scrutinize RNG paths more aggressively precisely because their users lack the technical sophistication to detect failures independently. The pursuit of an elite security reputation may have produced the conditions for this failure. The market response will favor Coldcard's competitors in the short term, but the implications extend beyond brand preference. Every hardware wallet manufacturer now faces pressure to demonstrate RNG path isolation through independent audit. Ledger and Trezor have not experienced similar disclosures, but the underlying cryptographic primitives are not proprietary to Coinkite. The probability that this class of defect exists in other vendors' implementations is non-trivial. Regulatory scrutiny of consumer hardware security products may intensify as a result, particularly if law enforcement confirms material losses attributable to the vulnerability. Coinkite's handling of disclosure has been professionally competent but not exemplary. The company moved quickly to publish patched firmware. They engaged Block for independent verification. They provided detailed migration documentation. However, the absence of confirmed victim counts or aggregate loss figures leaves the community to speculate about the actual impact. This opacity undermines trust recovery precisely when transparency would be most valuable. The current sideways market creates space for careful analysis, but users managing critical infrastructure cannot tolerate ambiguity about the severity of threats to their holdings. For users still operating vulnerable firmware versions, the path forward is unambiguous: migrate immediately. Generate the new seed using the physical entropy protocol. Verify the receiving address through independent means. Execute a small test transaction before committing the full balance. The complexity of this process is not a justification for delay. The probability of fund loss through a transition error is substantially lower than the probability of targeted exploitation against an identified vulnerable device. Silence in the code is louder than the contract, and the code has spoken clearly about the risks of inaction. The hardware wallet category will survive this episode, but the industry's self-congratulatory security narrative requires recalibration. Physical air-gap provides no protection against code logic errors. Open-source firmware offers verification only if anyone actually verifies it. The Coldcard incident demonstrates that security guarantees in this space are conditional on implementation quality, not on architectural assumptions. Users who understood this distinction beforehand have weathered the announcement with minimal disruption. Those who purchased devices as talismans against technical complexity now face the uncomfortable reality that their protection was conditional. Looking forward, the incident creates durable pressure for mandatory third-party audits of hardware wallet firmware, particularly the seed generation and signing pathways. Coinkite's engagement of Block represents a partial response, but the broader industry lacks any binding standard for independent security verification. This vacuum enabled the conditions for the vulnerability to persist undetected. Until verifiable audit trails become a baseline expectation rather than a post-incident response, similar failures remain inevitable across the category. The question is not whether another hardware wallet vendor will face an equivalent disclosure, but whether the next incident will receive the same degree of technical transparency when it arrives.

Coldcard's RNG Catastrophe: How a Flag Zero Became a Million-Dollar Problem

Coldcard's RNG Catastrophe: How a Flag Zero Became a Million-Dollar Problem

Coldcard's RNG Catastrophe: How a Flag Zero Became a Million-Dollar Problem

Fear & Greed

66

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xfa04...de23
Top DeFi Miner
+$0.1M
92%
0x22e6...973c
Top DeFi Miner
-$0.6M
84%
0xebfc...dd79
Market Maker
+$1.3M
89%