The Coldcard Compromise

In March 2021, Coinkite introduced an entropy bug into the firmware for their Mk3, Mk4, (and the yet to be produced Mk5 and Q) line. Instead of utilizing proper hardware-based entropy, the devices used software-based entropy partly predictable from the unique ID/serials, time/clock registers, and related states of their chips. The result: instead of utilizing 128 or 256 bit entropy, they were down to just 40 bits (for Mk3) or 72 bits (for the others), under optimistic assumptions. To grasp the difference in scale, see the video below. Essentially, the bug reduced the problem for the attackers from finding one atom in over a billion galaxies to finding one atom in a single organism. ...

August 27, 2026 · 352 words