We made a short visual explainer to help people understand the Coldcard bug, and what it means for the security of affected wallets.
Bitcoin's entire security model depends on a user's ability to select astronomically large numbers from a truly random set.
If you imagine every possible Bitcoin private key as individual atoms, when a private key is generated properly, the pool of possibilities is so large that it's like an attacker is hunting for one specific atom hidden somewhere across 2 billion galaxies. No classical computer could ever search that many possibilities.
Unfortunately, affected Coldcard firmware drew its seeds from a much smaller, more predictable pool. If every possible Coldcard private key was an atom, the possible set of keys would only be about the size of a large virus. In comparison, a standard computer could work through that space in just a few hours.
Our video helps visualize what this difference looks like, we hope this is helpful for everyone to establish the importance of true entropy in key generation.
We are deeply sorry for anyone who lost funds to this bug. We know several people that were personally affected, including members of the BPI team. Losing funds after working hard protect your wealth is extremely difficult.
We are developing a set of policy reflections based on this vulnerability that we hope to publish as soon as possible.
The yield on the 30-year Treasury is 5.18%, its highest since April 2006. At that time, the U.S. national debt was $8.35 trillion. Now it’s $39.6 trillion, almost five times as large. The U.S. can’t afford these rates, let alone the much higher rates we'll soon be forced to pay.