Privacy & SecurityIntelligence Snack

When randomness became predictable

A Coldcard firmware flaw turned private keys from secrets protected by an immense search space into numbers that attackers could recreate within hours.

Developed from a conversation between Pete Winn and Andy David

From Episode 66: The Coldcard Hack

Coldcard hardware wallets were supposed to generate private keys with a hardware source of randomness. A firmware change committed in March 2021 disabled that source and used a pseudo-random generator instead. The wallets could remain completely offline, but the keys protecting their Bitcoin were only as unpredictable as the limited inputs used to create them.

The replacement process combined a device identifier with other entropy that Pete understood to include timing information. That distinction transformed the economics of an attack. A genuinely random private key would be beyond the reach of all the computing power in the world, while one produced through the flawed process could reportedly be recovered on a laptop in a few hours.

Attackers could therefore reconstruct private keys without touching the devices and sweep funds from wallets whose owners had done nothing. Users who had added independent entropy, such as by rolling dice to generate seed material, were less exposed because their security did not rely solely on the faulty generator. The scale of the theft remained uncertain because public blockchain records cannot by themselves distinguish a stolen transfer from an ordinary one.

Get Intelligence Snacks in your inbox.

Quickly digest the big ideas emerging from the world of AI, delivered each week.