Physical entropy generation methods such as rolling dice are again drawing attention in cryptocurrency wallet security. [Photo: Shutterstock]

A low-entropy vulnerability in the Coldcard hardware wallet has surfaced, prompting bitcoin users to re-examine how they generate seed phrases. On Aug. 7, blockchain media outlet Cointelegraph reported that the community has recently focused on physical entropy generation methods such as rolling dice rather than relying on the wallet’s internal random number generator.

The issue was the quality of the random numbers used to generate seed phrases. Coldcard devices originally included STM32 hardware random number generation, but firmware 4.0.1 released in March 2021 used MicroPython’s Yasmarang pseudorandom number generator. The vulnerability was reported to have been introduced during a rewrite by Coldcard developer NVK to change the firmware from a GPL-licensed free software model to a read-only model.

Publicly confirmed theft cases also followed after July 30. Attackers brute-forced private keys derived from vulnerable seeds and stole more than $100 million in BTC. Coinkite estimated entropy at 40 bits for Mk2 and Mk3 devices, and about 70 bits for Mk4, Mk5 and Q. That falls well short of the 128 bits needed for a secure 12-word seed phrase.

After the incident, James O'Beirne (제임스 오베인) created a honeypot address site, cktripwire, to estimate what types of wallets attackers are actually sweeping. The likelihood of an attacker finding a wallet depended on whether users added extra dice entropy, used a BIP-39 passphrase and used non-standard derivation paths.

The community again highlighted the principle of “don’t trust, verify.” Users who did not rely on internal entropy generation and used enough dice rolls were able to avoid the vulnerability. By contrast, verifying a device’s internal random number generation requires physical inspection of electronic components and checking firmware, making it difficult for ordinary users to verify themselves.

As an alternative, methods to create physical entropy directly are again drawing attention. The most widely discussed approach is to roll dice at least 100 times to secure the entropy needed for a 24-word seed, then cross-check only that the device properly converts it into a BIP-39 seed phrase. Another proposed method, shown in a table released by BitBox, combines the outcomes of 6 dice rolls and coin tosses to choose seed words without electronic devices.

Another alternative mentioned was printing BIP-39 words on paper, cutting them to the same size, shuffling sufficiently and randomly drawing 24. Specialised hardware to distribute entropy generation across multiple devices was also proposed. Creating a seed from physical entropy can reduce single points of failure in the wallet creation process, and xpubs and deposit addresses derived from the seed can be cross-verified on another device.

Keyword

#Coldcard #Bitcoin #BIP-39 #Cointelegraph #Coinkite
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.