pull down to refresh

that a high-entropy passphrase

Thats actually a very good point. Hmmm....I know people have said that these were completely airgapped, so in theory we can rule out exfiltration.

A real high-entropy passphrase would seem to mitigate a RNG or library issue....unless the bug somehow affects CC private keys after a passphrase has been applied? Would be interesting to know if any users who did not have a passphrase have been compromised...

It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.

reply