Dudent

Market Prices

BTC Bitcoin
$75,894.5 -2.02%
ETH Ethereum
$2,405.17 -3.31%
SOL Solana
$97.2 -3.67%
BNB BNB Chain
$715.3 -0.63%
XRP XRP Ledger
$1.3 -7.60%
DOGE Dogecoin
$0.0803 -3.17%
ADA Cardano
$0.1957 -4.12%
AVAX Avalanche
$7.33 -2.11%
DOT Polkadot
$0.9530 -3.56%
LINK Chainlink
$10.88 -4.64%

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Tools

All →

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,894.5
1
Ethereum ETH
$2,405.17
1
Solana SOL
$97.2
1
BNB Chain BNB
$715.3
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0803
1
Cardano ADA
$0.1957
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.9530
1
Chainlink LINK
$10.88

🐋 Whale Tracker

🟢
0x4f39...dc6d
5m ago
In
3,864 SOL
🔵
0x1b5b...d1b5
2m ago
Stake
5,639,982 DOGE
🟢
0x626b...244a
6h ago
In
827,507 USDC

Coldcard's RNG Meltdown: Trust Failed Where Audit Passed

ETF | CryptoPanda |

A deterministic MicroPython fallback. A flag check that evaluated zero as present. A single line of code that turned Coldcard's vaunted hardware RNG into a fiction.

Block's independent analysis dropped the hammer on August 20. The root cause wasn't a hardware flaw. It was a logic error in the firmware's feature flag handling. When the flag defining the RNG call was defined as zero, the code routed the request to a deterministic fallback. Repeatable. Predictable. Private keys derived from entropy that wasn't.

Context: The Hardware Wallet That Wasn't

Coldcard occupies a specific niche in the Bitcoin self-custody landscape. Not the user-friendly Ledger with its glossy app. Not the open-source veteran Trezor. Coldcard is the air-gapped, military-grade option for the paranoid bitcoiner. The one who prints their own seeds, uses a faraday bag, and trusts no one.

That trust has a price. The Mk4 and Mk5 devices run on a custom firmware stack that prioritizes security over convenience. The RNG path is supposed to draw from a hardware entropy source, mixed with on-chain noise. But Block's analysis revealed that the code had a backdoor: if the feature flag for the hardware RNG call was set to zero (interpreted as a valid flag rather than absent), the system silently fell back to a deterministic MicroPython function.

This isn't a new vulnerability. The affected firmware versions span years. Mk2, Mk3, Mk4, Mk5, Q — all impacted. The scope is wider than Coinkite initially admitted. Block's analysis boundary was broader, and Coinkite acknowledged that.

Core: The Fix That Can't Fix the Past

Coinkite's response was swift. Within 48 hours of Block's disclosure, they released firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for the Q model. The fix: force manual entropy input. Users must now roll a dice 50 times or flip a coin 128 times to generate their seed. No more trusting the hardware RNG.

Effective. But not retroactive.

New firmware cannot add entropy to an already generated seed. Any wallet created on affected firmware is potentially compromised. The only safe action is to migrate to a new wallet with a new seed generated under the new firmware. That means sweeping all funds to a new address. For a Bitcoin maxi with a single large UTXO, that's a single transaction. For a privacy-conscious user with dozens of change outputs, it's a nightmare.

Audit passed. Trust failed.

Coinkite listed their target audits. They explicitly stated that not every binary fix was fully audited. The community is left with a partial audit trail and a manual dice-rolling procedure that introduces massive user error.

The migration itself is a risk vector. Coinkite published a detailed guide, but the human factor is the weakest link. Users who misplace their dice roll results, or fail to verify the seed on the device, or trust a compromised computer during the process — they are the next victims.

Contrarian: The Real Risk Isn't the RNG

Everyone is focused on the RNG vulnerability. The code flaw. The potential for stolen funds. But the greater risk is the migration itself.

Consider the math. A Coldcard user who has been on the same device since 2020, with dozens of transactions, multiple change addresses, and a complex UTXO set. That user now has to:

  1. Verify their current seed is on the affected list.
  2. Set up a new device with the new firmware.
  3. Generate a new seed using 50 dice rolls (ensuring fair dice, no bias, no recording).
  4. Write down the new seed correctly.
  5. Perform a test transaction with a small amount.
  6. Sweep all funds in a single transaction or multiple carefully crafted transactions.
  7. Double-check the new address on the blockchain.
  8. Destroy the old device.

Step 3 is where most will fail. The probability of a biased dice roll, or a recording error, or a lost seed phrase is non-trivial. Coinkite's own documentation admits that the dice roll exception is only for the most paranoid users. Most will use the hardware RNG again — which is now fixed, but the trust is gone.

The brand damage is permanent. Coldcard's core narrative was "absolute security." That narrative is now conditional. "Secure if you roll dice 50 times and trust our new firmware that hasn't been fully audited." That's not a sellable proposition.

Takeaway: The Industry's Wake-Up Call

This event isn't just about Coldcard. It's about the entire hardware wallet industry's reliance on opaque RNG paths. Ledger and Trezor have their own RNG implementations. How many of them have been independently audited for fallback logic?

Block's intervention is a positive signal. Independent analysis caught what internal testing missed. But the fact that internal testing missed it at all is a failure of process. Coldcard's internal QA should have included fuzz testing on the feature flag system. They didn't.

Beacon chain stable. Fragility remains.

The hardware wallet is the bedrock of self-custody. When that bedrock cracks, the entire house of cards trembles. Users will now demand audit reports for RNG subsystems. They will question the trust assumptions of every device. That's healthy. But it also means that the era of "just trust the hardware" is over.

For Coldcard, the path forward is clear: full transparency, complete audit of all firmware, and a user education campaign that makes dice rolling as foolproof as possible. For the rest of the industry, it's a warning. Code doesn't fail. Logic does. And when logic fails, trust doesn't recover overnight.

Fear & Greed

51

Neutral

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x1cb0...b256
Early Investor
+$4.4M
87%
0xbf23...9784
Experienced On-chain Trader
+$3.4M
87%
0x69d9...1a68
Market Maker
+$0.4M
95%