So many FUD around the coldcard incident

There’s nothing wrong with Bitcoin itself. The problem was the Coldcard itself and, more specifically, the weak entropy used to generate seed phrases on affected Coldcard firmware/devices. It’s a hardware/firmware implementation issue, not a Bitcoin issue.

Two years ago, there was already a similar issue with dice rolls: if you used too few dice rolls, your entropy was not sufficient. For a dice-only 12-word seed, you need at least 50 rolls; for 24 words, 99 rolls. (COLDCARD)

This has absolutely nothing to do with Bitcoin itself. It’s the company’s implementation and the developers’ negligence.

This video covered the dice/entropy issue around two years ago:
YouTube video

And the irony is that Coldcard itself has always marketed its device as one of the best and most secure options. I almost bought one back then too, until I saw that video.

If you’re using a different hardware wallet and its entropy generation is functioning properly, there’s no reason to reset everything just because of this Coldcard incident. Knowing that you checked everything and sure that the hardware provides a good entrophy and not just using rng.

The issue is with the vulnerable Coldcard implementation/firmware, not Bitcoin or hardware wallets as a whole.

A randomly generated 5–7 word passphrase can provide a huge amount of additional entropy. Words outside the BIP39 list can also be used, but what matters most is that the passphrase is genuinely random and not something you came up with yourself.

But at the end of the day, cases like this are going to discourage plebs from doing self-custody, and it is what it is.

Bitcoin itself didn’t fail here. The implementation did.

submitted by /u/unthocks to r/Bitcoin
[link] [comments]
Quelle: bitcoin-en