Bitcoin Forum
August 04, 2026, 08:18:36 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Should wallets warn users about low-quality entropy during SEED generation?  (Read 64 times)
satscraper (OP)
Legendary
*
Offline

Activity: 1540
Merit: 2875



View Profile
Today at 11:52:06 AM
 #1

Been thinking about this after the Coldcard drama.

Right now, most wallets software and hardware generate your SEED phrase and hand it to you with zero indication of whether the underlying randomness was actually good. No warning, no way to know.

In my view, it would be very welcome if wallets performed the relevant self checking  on the quality of the entropy used to generate  user's wallet, and warned  user if the entropy falls below, say, 128 bits. Either way, something as simple as: "Entropy below recommended minimum, proceed anyway? Yes/No" would at least surface the problem instead of silently handing someone SEED phrase that could potentially be compromised.

It's probably the right time to raise this matter with hardware wallet makers and software developers.

Curious what people think about this.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6469


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 11:58:03 AM
 #2

Example, how would Coldcard warn when its developers do not even know about it? Or maybe the developers know about it and are behind what happened.

Use open source wallet. Make use of passphrase that has strong characters or use a multisig wallet.

Adding your own protection (like passphrase or multisig) to it makes your wallet secure.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
satscraper (OP)
Legendary
*
Offline

Activity: 1540
Merit: 2875



View Profile
Today at 12:16:39 PM
Last edit: Today at 12:31:42 PM by satscraper
 #3

How would Coldcard warn that when its developers do not even know about it? Or maybe the developers know and are behind what happened.



ColdCard and other wallet developers could implement self-testing feature based on NIST SP 800-90B standard.


4.2 Types of Health Tests

Start-up tests: run after power-up/reboot, before first use. "The specific conditions in which the startup tests must be run for FIPS-validated cryptographic modules are determined by the requirements of FIPS 140."

Continuous tests: "run indefinitely on the outputs of the noise source while the noise source is operating... these tests are run continuously on all digitized samples obtained from the noise source, and so tests must have a very low probability of raising a false alarm."

On-demand tests: "can be called at any time... it does require that the entropy source be capable of performing on-demand health tests." Rebooting is an acceptable way to trigger these if it re-runs the start-up tests.




 Make use of passphrase that has strong characters orr use a multisig wallet. Add your own protection to it.

This is trivial routine for me, but not for many users. Smiley

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
hosemary
Legendary
*
Offline

Activity: 3206
Merit: 7149



View Profile
Today at 12:25:41 PM
 #4

Isn't the amount of entropy determined by the source of entropy and the algorithm the software uses to generate it? For example, if you generate millions of seed phrases through electrum, they all will have 132 bits of entropy, regardless of the final results.
Also, even if the algorithm is flawed, the final result will still look completely random and there is no way to tell how random it is just by checking the final result.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
satscraper (OP)
Legendary
*
Offline

Activity: 1540
Merit: 2875



View Profile
Today at 12:58:54 PM
 #5

Isn't the amount of entropy determined by the source of entropy and the algorithm the software uses to generate it?

Hardware noise sources may fail or degrade. But what would be suitable for given hardware wallet to catch the software bug the current ColdCard case that swaps out the hardware entropy source and  produces the plausible looking but predictable output I don't really know. That is why I have raised the discussion here.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Mia Chloe
Legendary
*
Offline

Activity: 1148
Merit: 2257


Contact me for your designs...


View Profile
Today at 01:41:41 PM
 #6

Been thinking about this after the Coldcard drama.
Right now, most wallets software and hardware generate your SEED phrase and hand it to you with zero indication of whether the underlying randomness was actually good. No warning, no way to know.
First off, just like charles tim mentioned, no one was really aware of the firmware issue basically because if they were aware in the first place the developers would have notified them fixed it and that theft wouldn't have happened to start with, most walllets don't even give you option to change where your entropy comes from.

The average bitcoiner isn't even conscious about entropy and many people till date don't even know you can generate you own entropy source yourself and use it to hash for your seed phrase. To avoid complexities generally it's just best you pick the safest form of entropy generation you can get and allow softwares use it instead of complicating things.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Zaguru12
Legendary
*
Online Online

Activity: 1498
Merit: 1255


Instant Crypto Withdrawals


View Profile WWW
Today at 01:52:32 PM
 #7

Isn't the amount of entropy determined by the source of entropy and the algorithm the software uses to generate it? For example, if you generate millions of seed phrases through electrum, they all will have 132 bits of entropy, regardless of the final results.
Also, even if the algorithm is flawed, the final result will still look completely random and there is no way to tell how random it is just by checking the final result.

Exactly the question I wish to ask about the randomness is that isn’t the software of the wallet actually unaware of the degree of the randomness? From my knowledge I think it’s dependent on the underlying software (or after generation they employ NIST to check) and this why in CSPRNG I have read about using Linux been one of the best. 

I think with this a wallet can not identify the true degree its randomness. The only reason why I think most people are challenging or blaming cold card is simply because there was reports that their system source (TRNG) wasn’t that random as it was broke but they didn’t take that warning or acted upon it and it was what lead to this, which is why I also call for them to be blamed

First off, just like charles tim mentioned, no one was really aware of the firmware issue basically because if they were aware in the first place the developers would have notified them fixed it and that theft wouldn't have happened to start with, most walllets don't even give you option to change where your entropy comes from.

Wasn’t there many warning about this flaws in the past, I have been reading about many links long this forum about that this flaw

internetional
Legendary
*
Offline

Activity: 2254
Merit: 3440



View Profile WWW
Today at 02:17:36 PM
 #8

Given what happened to Coldcard, if I were the developer of any wallet that generates seed phrases, I would audit the generation mechanisms used in every single version of my wallet. If it turns out that unreliable randomization tools were used, it is critical to find a way to urgently notify users - or at least the wider public, even if that might trigger a hunt for the discovered vulnerability. For instance, I heard somewhere that the Nunchuk wallet generated its private keys using Coldcard. If that is the case, it needs to be reported. On the flip side, if the audit shows that the randomization was always strong, that is also worth sharing.

On another note, I have seed phrases generated by wallets that are no longer supported by their developers. Just to be safe, I think I will stop using those seed phrases altogether.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
hosemary
Legendary
*
Offline

Activity: 3206
Merit: 7149



View Profile
Today at 02:18:52 PM
 #9

Hardware noise sources may fail or degrade. But what would be suitable for given hardware wallet to catch the software bug the current ColdCard case that swaps out the hardware entropy source and  produces the plausible looking but predictable output I don't really know.
The problem is you can't tell how good the randomness is just by checking a single seed phrase.
If you want to determine whether the generated seed phrases are truly random or not, you have to generate a large number of seed phrases, and analyse them to see if they cover the entire 128 bit space uniformly.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!