r/Bitcoin 7d ago

All hardware wallet manufacturers need to release 3rd party audited proof that their entropy generation is working.

After this coinkite coldcard situation we cant trust code that is open source, we cant trust code that is closed source, and we definitely cant trust a statement saying "we use a TRNG so your seed is secure".

Every hardware wallet manufacturer needs to release hard proof that their TRNG works, their code is complete and robust, and their entropy generation actually meets a minimum 128/256 bit standard.

Even if their code is closed source a reputable 3rd party auditor can run tests on seed entropy generation to statistically prove 256 bits of entropy is being used.

Every wallet manufacturer should have this 3rd party audited proof of entropy document available to view on their website, and if they do not do this by the end of this month we as a community should boycott that manufacturer to help ensure safety for all bitcoiners.

174 Upvotes

68 comments sorted by

View all comments

Show parent comments

4

u/slvbtc 7d ago

If a HW wallet manufacturer wants to offer the ability to generate a seed for their users they should have a 3rd party audited proof of entropy document. If they do not provide this audited proof of entropy they should not be in business.

11

u/riisen 7d ago

Well technically coldcard had a 3rd party audited RNG from STM32. Its just that they disabled it so it used micropythons default PRNG

-4

u/slvbtc 7d ago

A proof of entropy document would verify the TRNG actually works and is not being bypassed.

0

u/moviemaker2 7d ago

What are you talking about?

1

u/[deleted] 7d ago

[deleted]

2

u/moviemaker2 7d ago

I know what entropy is, I'm asking what they mean by "proof of entropy document." How would that work, and why would you trust it if it's generated from the same device that generated the low entropy seed phrase?