Firehose

Filtered to tagged “entropy exposure” · clear filters

All PeopleCompaniesPapersPodcastsHacker News

Browse by tag

30 JUL 2026 · Block

A COLDCARD firmware vulnerability allows for theft of Bitcoin funds due to a predictable RNG fallback and 32-bit reseed. The RNG uses a deterministic fallback and limited secure-element reseed, constraining entropy across COLDCARD generations. This can be exploited by an attacker who knows the device's UID, timer state, and RNG-call history. AI summary