I think most of us must have seen the news around Coldcard compromised, it was actually highlighted on the news section on the forum visible for everyone to see;
coldcard compromisedI know many will be actually surprised because its primarily about hardware wallet which are considered safe but that is the reason why not all hardware are actually good for use.
This coldcard wallet was initially an open source wallet but right now it’s a source verifiable, what this means is that you can check the source code to verify it but cannot legally use it on your project, what this means is that less developers will pay attention to it, because after all I can actually look into something that will be beneficial to me too. With few developers looking into it means less people finding the vulnerability or errors like randomness in creating seed phrases and this is clearly similar to closed sources too.
How was this attack pulled off The attackers actually found a vulnerability in the RNG, that’s the randomness associated with the generation of seed phrase, we all know that the security of your wallet is basically on randomness and entropy which 128bits is just secure enough, so if your wallet software uses a weak PRNG generator it’s easier for attackers to actually find the vulnerability by getting a weak seed that is part or starts the generator and it’s around here that this coldcard vulnerability came from.
Extent of the attack so far The attackers were sweeping addresses with at least 0.15 bitcoin base on the addresses posted running across 500 transactions, with total number of bitcoin stolen totaling over 1000 so far.
What should you do 1. First instance will be to not trust hardware wallets to actually generates your seeds for you most especially closed source or similar hardware wallets and the best thing is to generate your own seed phrases either manually by picking the words yourself and allowing a wallet to generate the last word for you only for checksum
2. or use open source wallets like electrum in an offline environment before Importing into your hardware wallet
3. use passphrase which are strong enough or make use of multi sig with most co-signers if not all generating seeds as described above.
This saves you from hardware wallet firmware attacks like this of coldcard
4. Test this wallet first and back up all seed phrases and passphrase properly.
Who should be scared now I will say if you’re using closed source wallet or even hardware wallets like ledger which extract yours seeds for you phrase for recovery then you should simply sweep your bitcoin to a new wallet