pull down to refresh

My bet is this: Someone who doesn't deeply know bitcoin has used AI to scan for vulnerabilities in RNG and or libraries used in CC.

They have identified some bug that produces a reduced search space (low entropy) and are generating random wallets in this reduced space and getting some hits, but due to their lack of bitcoin knowledge they (or more likely claude script) is only partially draining .

Real mess, feel for those affected. Time will tell....

as per #1536330?

In which case I guess I ask what is low entropy? CC has supported supplementary dice roles and passphrases on top of the wallet generation process, is that higher entropy or does it not matter for reasons?

reply
CC ha supported supplementary dice roles and passphrases on top of the wallet generation process, is that higher entropy or does it not matter for reasons?

Can't tell right now. If a bug is sitting in the RNG, yes it helps. If the bug is in the combination or derivation mechanism, no it does not help.

reply

We're not sure. I would think that a high-entropy passphrase or added seed entropy would protect from the attack but check twitter for the latest info.

reply
114 sats \ 1 reply \ @freetx 30 Jul
that a high-entropy passphrase

Thats actually a very good point. Hmmm....I know people have said that these were completely airgapped, so in theory we can rule out exfiltration.

A real high-entropy passphrase would seem to mitigate a RNG or library issue....unless the bug somehow affects CC private keys after a passphrase has been applied? Would be interesting to know if any users who did not have a passphrase have been compromised...

reply

It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.

reply