When Your Recovery Phrase Isn’t Random Enough
More than $100M worth of Bitcoin has been linked to thefts involving a weakness in COLDCARD seed generation.
The surprising part: attackers did not need to steal the hardware wallet, connect to it, or know the PIN.
The problem started when some wallets created their recovery phrase.
COLDCARD disclosed that affected firmware did not always get randomness from the hardware random-number generator as intended. In some cases, recovery phrase generation could fall back to a much more predictable s