All Crypto Blogs

Bitcoiners turn to dice throws as self-custody setups are re-evaluated

cointelegraph.com · Aug 7, 2026 at 13:00

Bitcoiners turn to dice throws as self-custody setups are re-evaluated
cointelegraph.com Aug 7, 2026

Dice entropy may become the new gold standard after the Coldcard hack

In light of the catastrophic low-entropy bug in Coldcard hardware wallets, linked to publicly observed thefts beginning on July 30, Bitcoin holders have started to re-evaluate the trust assumptions in their hardware wallet setups. 

The Coldcard devices were equipped with apparently functional STM32 “true random number generators” (TRNGs) that rely on physical processes to produce an unguessable seed phrase.

However, after Coldcard creator NVK decided to initiate a firmware rewrite to switch from a GPL-licensed free software model to a read-only model, a serious vulnerability appears to have been introduced.

Starting with firmware version 4.0.1, released in March 2021, the device used MicroPython’s Yasmarang PRNG instead of properly using the STM32 hardware RNG.

Random number generation is an unsolvable problem in computer science, which is why the generation of secure, unguessable private keys always has to rely on external physical processes to a degree. 

The use of the Yasmarang PRNG was widely characterized by analysts in the space as a pre-programmed fallback. However, Coinkite has now disputed this characterization in a recent X post: 

The conjecture that Coldcards were programmed to default to an obviously insecure method of seed generation has also sparked speculation on X about whether this was a deliberately placed backdoor. 

Investigative Bitcoin journalist Hodlnaut speculated that the bug stemmed from careless development practices and efforts to suppress errors through random changes.

Coinkite estimated that Mk2 and Mk3 devices generated seeds with 40 bits of entropy, while the Mk4, Mk5 and Q achieved around 70 bits. Both are well short of the 128 bits required for a secure 12-word seed phrase.

Ever since then, attackers have been successfully brute-forcing private keys, stealing over $100 million worth of BTC. How likely a wallet is to be found depends on whether or not additional dice entropy was added, or a BIP-39 passphrase and non-standard path were used. 

Related: Coldcard hackers transfer 64 BTC and 200 ETH to cryptocurrency mixers

Source

This article is syndicated for educational reading. For the latest updates, visit the original publisher.

Read on cointelegraph.com

Recently Used