When the Coldcard release a new version of the solid, some users are asked not to continue using the old assistive words. The company disclosed that if the assistive words were generated in the affected version, the user would need to upgrade the equipment, then build a new wallet and transfer Bitcoin to the new wallet address. Installation of an update alone would not fix the defects of the old assistive word itself.

Add new solids to manual random input

This release includes 5.6.1 for Mk4 and Mk5 and 1.5.1Q for Coldcard Q. According to the company, a security review has been conducted over the past three weeks of the problem of the production of assistive words and the signing of the transaction, the equipment connection, the installation of solids, and the random number check.

Upon updating, all newly generated assistive words must be added to the random input provided by the user and cannot rely solely on a random source within the device.

  • At least 65 key entries
  • 50 private rolls of six dice.
  • 128 private coins.

Coldcard indicates that the equipment will mix these with STM32 real-random generators and data from two security components SE1, SE2 to reduce reliance on a single random source.

The old assistive word has to be upgraded and replaced.

The company disclosed that the affected users should verify the signature of the solids and then create and verify a new set of assistive words and then transfer Bitcoin to the address controlled by the new wallet. If the old assistive word is imported into the updated Coldcard, other hardware wallets or software wallets, the original weakness will remain, as the problem arises at the drafting stage of the helper, rather than the way the wallet software is read.

Coldcard suggests that the user offline record new assistive words, confirm the receipt address on the device screen and make a small test transfer before moving the full balance. The old backup could be retained for the time being, but should not continue to be used to receive funds, pending confirmation of the completion of the relocation.

  • Mk2, Mk3: 4.0.1 to 4.1.9
  • Mk4, Mk5: Standard version 5.6.0 or Edge version 6.6.0X affected
  • Coldcard Q: Standard 1.5.0Q or Edge 6.6.0QX affected

Mk1 is not in the context of this solid retrogression problem. TAPSIGNER, OPENDIME and SATSCARD use different software and are not subject to the same disclosure.

The loophole is due to the lack of randomity of assistive words.

This update also enhanced the process of checking transactions before signing. According to the company, the new version would verify the PSBT in stages before signing and adjust the default SIGH processing, while tightening the USB connection and the solids to update the relevant boundary to complement the random number initialization and abnormality check.

This problem can be traced back to a solid change in March 2021. The Bitcoin Engineering and Security Team in Block had previously indicated that the affected software, in generating wallet aids, had called for a definitive MicroPython regression path rather than the STM32 hardware random number generator that should have been used.

According to the Block analysis, the more old Mk2 and Mk3 devices generate assistive words with an effective randomness of about 40 bits; while the risk Mk4, Mk5 and Q devices have some security component input, the overall randomity is still about 72 bits, down from the expected 128 bits. This means that some of the assistive words may be overloaded.

Additional information:The researcher ' s follow-up analysis stated that this defect could have involved four rounds of attack, involving more than 5,200 addresses, and that it was estimated that approximately 1816 BTCs had been removed. Following the incident, some users transferred bitcoin to the custody of the Centralized Exchange.