<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Hardware-Wallet on blog.nath.page</title>
    <link>https://blog.nath.page/tags/hardware-wallet/</link>
    <description>Recent content in Hardware-Wallet on blog.nath.page</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 27 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.nath.page/tags/hardware-wallet/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Coldcard Compromise</title>
      <link>https://blog.nath.page/posts/coldcard1/</link>
      <pubDate>Thu, 27 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://blog.nath.page/posts/coldcard1/</guid>
      <description>&lt;p&gt;In March 2021, Coinkite introduced an entropy bug into the firmware for their Mk3, Mk4, (and the yet to be produced Mk5 and Q) line. Instead of utilizing proper hardware-based entropy, the devices used software-based entropy partly predictable from the unique ID/serials, time/clock registers, and related states of their chips.&lt;/p&gt;
&lt;p&gt;The result: instead of utilizing 128 or 256 bit entropy, they were down to just 40 bits (for Mk3) or 72 bits (for the others), under optimistic assumptions. To grasp the difference in scale, see the video below. Essentially, the bug reduced the problem for the attackers from finding one atom in over a billion galaxies to finding one atom in a single organism.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
