COLDCARD weak-randomness warning focuses on single-signature wallets without passphrases

Posts by SlowMist’s Cos and Galaxy’s head of research said affected COLDCARD setups involve firmware dated March 17, 2021 or later and can be mitigated by higher-entropy seed generation or a passphrase.

Summary

Security warnings about weak random number generation in COLDCARD hardware wallets centered on single-signature setups created with firmware dated March 17, 2021 or later, without dice rolls or a passphrase. Galaxy’s head of research said such wallets may be wiped and urged users to stop using affected devices unless they imported a high-entropy seed from another source or generated the wallet with multiple dice rolls. SlowMist’s Cos said a passphrase attached to the seed phrase, distinct from the wallet unlock PIN, can block the attack, noting that mainstream hardware wallets support the feature.

Terms & Concepts
  • passphrase: An extra password attached to a wallet’s seed phrase, separate from the device unlock PIN.
  • single-signature: A wallet setup in which one private key is sufficient to authorize transactions.
  • seed entropy: The randomness used to generate wallet keys; weak entropy can make keys easier to predict or recover.