Reddit Posts
Mentions
That’s a misunderstanding of the bug. Even if it were: >!\#define USE\_ENTROPY (1)!< it would still have had the bug because they had a downstream conditional like this: >!\#ifndef USE\_ENTROPY!< … software entropy here >!\#else!< … hardware entropy here >!\#endif!<
There's like bazillion sources for entropy, starting from built-in transistor noise amplifier which is quantum random by definition. None of it matters if someone compiles in #define USE_ENTROPY (0)
LOW\_ENTROPY\_NOT\_SKIPPED\_IF\_SET\_TO\_NOT\_TRUE = 0 This is how I imagine cold cards config flags
It only impacted people who tried to let a computer generate a random number. Idk why anyone wouldn't have bought some dice and set their own random numbers. ENTROPY MAN
THE ATTACKER DID NOT BRUTE FORCE PRIVATE KEYS. The attacker brute forced the range of up to 72 bits of ENTROPY to find seeds that produced addresses with UTXOs. That's VERY, VERY different from brute forcing a 256 bit private key.
Single sig, there is seed signer, bitbox, even trezor is okay, and for multi-sig, theres bitkey or even unchained is great collaborative custody.. but heres the thing, you can even still use a coldcard if you want (even after this recent exploit of their mk2 & mk3 default Random Number Generators) because it is CRUCIAL that no matter what seed you create on a cold device, make SURE to fully incorporate dice rolls and/or coin flips for FULL ENTROPY(randomness) rather than rely on whatever the device’s claimed RNG(Random Number Generator) default seed generator gives you, thats the main thing we need to spread in the BTC community after this horrible incident involving coldcard. 🧡