pull down to refresh

We're not sure. I would think that a high-entropy passphrase or added seed entropy would protect from the attack but check twitter for the latest info.

114 sats \ 1 reply \ @freetx 30 Jul
that a high-entropy passphrase

Thats actually a very good point. Hmmm....I know people have said that these were completely airgapped, so in theory we can rule out exfiltration.

A real high-entropy passphrase would seem to mitigate a RNG or library issue....unless the bug somehow affects CC private keys after a passphrase has been applied? Would be interesting to know if any users who did not have a passphrase have been compromised...

reply

It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.

reply