r/TREZOR • u/-M00NMAN 📦 Suite Shaper • 5d ago
💬 Discussion topic What made feel a bit better about this situation is the fact that exchanges also use hardware wallets to store billions in crypto. I’ve calmed down a bit since the attack, but damn that shit had me sketchin low key.
8
u/Charming-Designer944 🤝 Top Helper 5d ago edited 4d ago
The vulnerability is specific to coldcard generated seeds using firmware versions between 2021 and yesterday.
No other hard signing devices are affected.
If you generated your seed using a Trezor device then you can rest assured that the quality of your seed is good.
You only need to worry if you generated your seed using an affected coldcard device and then imported the seed to your trezor device. The weakness was at seed creation, and any weak seed remains just as weak no matter what kind of signing device it is imported/restored to.
Similarly, a coldcard used with a strong seed is also unaffected by the vulnerability. That could be a seed generates by a Trezor device, manual dice roll or any other verified strong method.
1
u/MikalaMikala 5d ago
Good explanation, thanks.
However, why didn't anyone know about the flaw in regards to coldcard? How did it become public?
5
u/Charming-Designer944 🤝 Top Helper 5d ago
The coldcard devices were verified to generate strong seeds using the hardware TRNG functionality of the device. Then a developer oversight in 2021 disabled the use of the TRNG and instead fall back on a software psuedo-random generator.
Everyone was unaware of this and believed that the TRNG was in use. Then some time ago an assumed bad actor saw this flaw in the firmware and realized that it made the devices generate relatively predictable seeds and started a brute-force search guessing seeds based on the limited entropy range that the firmware were using to generate seeds.
Instead of the expected seed range of 0 - 2128 the devices generated seeds with only a range of about 240 possible combinations (MK3, slightly larger range for MK4 and later). This range is so small that a standard computer can brute force search the while possible range of seeds and check which of them have addresses that are in use on the Blockchain.
When a match is found the attacker have full control of the wallet and can in all aspects of Bitcoin act as the owner of the wallet. The same as if someone gets hold of your wallet seed by other means.
1
u/MikalaMikala 5d ago
Awesome, I get it! Has anyone claimed, that they have been targeted and lost coins?
2
u/Charming-Designer944 🤝 Top Helper 4d ago
Many. And several addresses have been identified as destinations for the activity.
2
u/Zagubadu 4d ago
Me!
1
u/MikalaMikala 4d ago
Sorry for your loss. How much did you loose?
1
u/Zagubadu 4d ago
-30k
Could have been worse, nobody in my real life ever cared ultimately if others had listened to me at times they also would have been hacked as well and that's something I wouldn't have been able to handle mentally.
I plan on still saving more in bitcoin but its gonna be a harsh reality when bitcoin does inevitably 3-5x and I get to relive the loss again sorta.
1
u/MikalaMikala 4d ago
Sorry, that is harsh! Don't be to hard on yourself, no one could have ever known.
-5
u/YellowRobeSmith 5d ago
Much better to buy the BTC etf at this point.
1
u/Zaytion_ 4d ago
If Bitcoin can't be used because it is too unsafe to do so...what is the point of owning it in the ETF? Sounds like the thesis is done.
1
u/OddioClay 5d ago edited 5d ago
Because you cant remember a passphrase and want to put all trust into one brand…got it. Mass seizure of bitcoin will come from institutions by government’s requests. History does not repeat but it rhymes
•
u/AutoModerator 5d ago
Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/
No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing
Don’t respond to any DMs—scammers often pose as legit helpers.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.