r/Bitcoin: about the recent Coldcard attack
reddit-bitcoin-early-explanation
https://www.reddit.com/r/Bitcoin/comments/1vbnvzn/about_the_recent_coldcard_attack/
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vbnvzn author: Prestigious_Ear_8055 created_utc: 1785496125 title: About the recent coldcard attack body: I’m trying to understand the security vulnerability of any cold hardware device. Since the attacks targeted coldcards specifically, it means the RNG of coldcard seed generations got figured out and they were able to brute force the secret phrase. Meaning the secret phrase generated by coldcards were predicted and narrowed down, the possibilities were NOT astronomical (they never were to begin with technically?) However, this does not mean any secret phrase can be brute forced Even cold devices with weak 12 words generation for example, cannot be targeted randomly by brute force since the possibilities are still enormous, UNLESS THE RNG of the device used to generate the secret phrase gets figured out and possibilities get narrowed down. So each cold device has its own entropy, meaning for 12 astronomical possibilities of words to get figured out exactly as they are would require software breach of the cold device Is this analogy true? Even if you don’t use passphrase, secret phrases in general are not at risk unless their main RNG gets figured out. But does this mean no cold device is truly random? Also if someone downloads a cold wallet from a trusted source, runs it on an old laptop. The seeds generated will not ever be brute forced unless the laptop’s antropy gets figured out (time etc) ? One final question and it gets a bit complicated. Is using a random old device, like a laptop, to generate seed phrases (offline airgapped of course) safer than using a globally known cold wallet brand? Meaning figuring out a random laptop’s time and ram usage when seeds were created is near impossible if a hacker doesn’t know you have a cold device on that laptop model specifically, unless he gets his hands on it or has to emulate it (but won’t know settings you haed?) compared to having a publicly known cold wallet brand which many people use with one software entropy? comment: p0upe8p parent: t3_1vbnvzn author: frugaleringenieur created_utc: 1785496308 edited: false body: To your assessment how the ColdCar incident played out - yes, quite accurate. Regarding your other questions: the best creation of entropy is always without a computational electronic device. Creating a good random number generator is hard on its own. Having a minor bug can have catastrophic consequences on top.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.