@zherbert@FoundationHQ I ran it against LLMβs, broken error check on the avalanche source, the seed task discarding the failure return, asserts compiled out in release. I did not verify the claims myself line by line
@Mandrik As much as I like the company, they have shown real neglect on their end. Any seed related code should have been reviewed 1000x over. I canβt really bring it up feel sorry for them, they have cost people their life savings, there is no excuse
MK4s are vulenerable but are millions of times harder to steal from. MK3s can be stolen from a decent laptop, mk4,5s and Q would need much more compute.
The model:
- attacker has a roughly 2^20 UUID range that it knows cold cards fall in
- checks a 16 button press variancer in user behavior before generating the seed
You should still promptly remove funds from mk4,mk5 and Q.
MK4s are vulenerable but are millions of times harder to steal from. MK3s can be stolen from a decent laptop, mk4,5s and Q would need much more compute.
The model:
- attacker has a roughly 2^20 UUID range that it knows cold cards fall in
- checks a 16 button press variancer in user behavior before generating the seed
You should still promptly remove funds from mk4,mk5 and Q.
MK4s are vulenerable but are millions of times harder to steal from. MK3s can be stolen from a decent laptop, mk4,5s and Q would need much more compute.
The model:
- attacker has a roughly 2^20 UUID range that it knows cold cards fall in
- checks a 16 button press variancer in user behavior before generating the seed
You should still promptly remove funds from mk4,mk5 and Q.
@BitBoxSwiss This would be a good time to scrutinize your own code, a lot of people are hurting. No time to celebrate or advertise on this kind of event
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis.
Read the advisory and migrate carefully:
https://t.co/3vgPHOjMS7