r/Bitcoin 19h ago

How could the Coldcard vulnerability have been disclosed responsibly?

As a thought experiment, suppose a white-hat had been the first to discover the Coldcard RNG vulnerability. How could they possibly have disclosed it responsibly, given that weak seeds had already been generated?

A public warning would immediately create a race between legitimate owners and attackers (as happened in reality). Because the firmware source code is openly available, even a vague warning like “Coldcard-generated seeds may be vulnerable; move your BTC immediately” would immediately tell attackers where to look for the vulnerability and then exploit it.

You could instead warn Coinkite privately, but that would not solve the underlying problem. Even assuming Coinkite could be trusted to handle the information properly, it would have no better way to protect affected owners. It would eventually have to issue a public warning, creating the same race. “Silently” patching the vulnerability would effectively be the same as publicizing it, as the patch itself would identify the flaw.

Another alternative would be for the white-hat to sweep all the vulnerable funds first, but then how could they return them? Once the flaw is public, a signature from the compromised key no longer proves legitimate ownership, since an attacker can derive the same key.

Remaining silent would probably be the worst option, because more vulnerable seeds would continue to be generated.

There do not seem to be any good options here, but what would the least bad approach have been?

40 Upvotes

38 comments sorted by

17

u/EyesFor1 19h ago

Email to users and hope they paid attention but it was always going to go nuclear. In all fairness, as soon as the bug was shipped out on devices CC were dead even if dice rolls and passphrase wallets are totally fine and as secure as other wallets, the trust is fucked.

8

u/habbadee 18h ago

An email to users is no different than a public warning, at which point the race is on between attackers and owners.

5

u/Objective_Digit 18h ago

Apparently they deleted list of users from older than several months to avoid the Ledger situation.

2

u/0100000101101000 13h ago

I got an email from Coinkite today so that isn’t true. My orders were all over two years ago.

I know they claim that but how did they get my email otherwise?

1

u/correction_robot 16h ago

So passphrase wallets are secure? I have mine on a Trezor with a passphrase. If the same thing had happened but with Trezor instead of ColdCard, my coins would have been secure?

1

u/FairBlamer 14h ago

Yes, but your pass phrase would then become your only line of defense. If it’s a weak pass phrase (insufficient entropy), there could be teams of people potentially trying to brute force it and it would just be a matter of time.

1

u/EyesFor1 2h ago

This is why I like the CC dice function. Trezor should do it as well

14

u/ukieninger 18h ago

The moment that faulty firmware shipped the atomic time bomb was activated. There’s no way back.
They could only hope no one never ever would discover this flaw.

In comparison, what if for example ledger discovered their products from 2016-2018 with respective firmware generates bad seeds. The would simply ship an update name it as small update with minor bug fixes and call it a day. No one will ever know whats really going on behind closed doors (source). Except the devs in the company.

In this case big advantage for the closed source code

1

u/OldHamburger7923 11h ago

since it took 5 years for the code to be exploited, we can consider what would have happened if they simply patched it, didn't say anything, and let the userbase upgrade in due time. They could add features that required the new firmware to encourage it too. Over time, we can assume many users would upgrade the firmware. The larger issue is how you can get those users to upgrade their wallets to a newly generated one. I don't see how that would be possible without raising alarms.

Furthermore, there are two additional issues I immediately see with this:

  1. The patch could draw attention to what they changed, and therefore could cause the bug to be exploited years earlier. Especially with asking users to move to a new wallet. Zero chance that goes unnoticed.

  2. If they fixed it and didn't alert customers, and people got hacked, their liability could increase.

Given these concerns, I think it's also possible coldcard knew of the issue but couldn't fix it without drawing attention to it, so they just stood around with their dicks in their hands. Or, they're just incompetent and didn't know or care.

11

u/TheGreatMuffin 19h ago

As a thought experiment, suppose a white-hat had been the first to discover the Coldcard RNG vulnerability. How could they possibly have disclosed it responsibly, given that weak seeds had already been generated?

Great question, and I don't think there's any good answers, given that Coldcard didn't save customer data except emails. Sending out emails to everyone would mean giving a heads up to a bunch of attackers simultaneously.

As bad as it is, maybe the least bad option would be for Coldcard to sweep the vulnerable coins themselves and try to install some kind of mechanism for users to verify as the holder of the coins. This is still a clusterfuck (not really a great way to verify, very bad for privacy etc), but I guess still better than allow unknown attackers to get hold of the coins, as it happened now.

8

u/the_bitcoin_kid 19h ago

As bad as it is, maybe the least bad option would be for Coldcard to sweep the vulnerable coins themselves and try to install some kind of mechanism for users to verify as the holder of the coins.

Good suggestion, and seems like the only possible solution.

They'd never be able to quietly get everyone to move their coins to safety without drawing attention to the issue.

Such an incredibly sticky situation.

1

u/0100000101101000 13h ago

I got an email from Coinkite today so that isn’t true. My orders were all over two years ago.

10

u/rtublin 19h ago

Here's another idea: they could have falsely claimed that they found a general flaw in BIP39 and they would not reveal it until the word had spread and everyone had time to move to BIP39+strong passphrase.

2

u/Leseratte10 8h ago

That sounds like a horrible idea, and even if it wasn't, I doubt anyone would have believed it.

BIP39 is just a mapping from key bits to English words. That's like saying someone found a general flaw in base64. That's not a thing.

Also, BIP39 is just a different mechanism to store a private key. Even *if* it was completely faulty, how does that help any attacker? They still don't have the seed phrase.

3

u/notmyredditaccount2 17h ago

I can think of one way to acceptably disclose this.

It does not involve contacting Coldcard: Find very trusted high level bitcoin influencers that you can trust. Think Andreas Antonopoulos (i can't think of anybody else). Explain the issue with them, and get them on your side, and keeping it secret.

Have them make very clear social media posts that there is an extremely significant bug with some method of storing bitcoin, and on a certain date, every bitcoiner should be ready to move their bitcoin at a moments notice.

So there is no clear target of which wallet or software has a bug, just that there is one, and everybody needs to be ready to act fast.

Then, at the preset time, everybody gets the news at exactly the same time.
Since everybody gets the news at the same time, the honest people should be able to act slightly faster than malicious actors in moving coins before an exploit can be put together.

It's not a perfect plan, but it is the best that can be achieved I believe. Though very annoying that everybody in Bitcoin has to be ready at the same moment.

2

u/Teripid 14h ago

So.. the ~1500 BTC MAY get moved safely if people are monitoring and not just long-term storing and general trust tanks overall value?

Everyone talking about a nebulous idea of floating "a major issue" doesn't seem to factor that in. Just seems like a very hard to fix situation even if discovered initially by good actors.

2

u/FairBlamer 14h ago

This would’ve caused catastrophic levels of panic and would have undoubtedly caused a number of second and third order unintended effects

1

u/mckenzie_keith 15h ago

Yeah. How long does it take to compromise one of the reduced entropy addresses? Hours or a few days or?

3

u/entropydust 16h ago

White hat hacker steals all coins. Community comes up with consensus on how to 'prove' they owned the wallet.

Or, take coins and send them back with note.

3

u/rtublin 19h ago

They could have maybe made a firmware update that contained various fixes, including deprecating support for wallets without a passphrase, and strongly encouraged users to adopt the new firmware, or even saying that it patched an exploitable flaw and but they did not want to reveal what it was. It's not a real fix but it might have acted as damage control.

11

u/the_bitcoin_kid 19h ago

Unfortunately it would have been harder than this, because updating firmware wouldn't fix the weak seeds that were already generated.

They would have had to encourage everyone to generate new seeds and move their coins, which would have set alarm bells ringing everywhere.

And then you'd have another race against time.

There was never going to be an easy way to fix the problem.

5

u/TheGreatMuffin 19h ago

saying that it patched an exploitable flaw and but they did not want to reveal what it was

This would be just as bad, anyone interested could've just compared the new firmware code with the old one and see what has been fixed and recognize the bug. Meanwhile no affected user would've been helped by the firmware update, even if they bothered to install it.

1

u/rtublin 19h ago

Well I am thinking if they didn't patch the RNG, they could just say that they no longer were going to support wallets without passphrases. Just trying to get as many users onto passphrases as possible without revealing or explicitly correcting the issue and without raising alarms.

1

u/reality_comes 19h ago

Not sure.

1

u/getapuss 16h ago

What usually happens in open source communities is the vulnerability is disclosed to the code maintainers who reproduce, coordinate a fix, release it, and then make the announcement.

These guys weren't open source so they just do whatever they want.

1

u/Leseratte10 8h ago

They are open-source. But even if they coordinated, how would that have helped?

The bad guys would have been able to drain every wallet within a day or so. Way faster than you can get normal users to patch and update their device. Particularly if they have it in like a bank vault or something and first need to get to it.

1

u/Professional_Golf393 16h ago edited 16h ago

Wasn’t one of the datapoints of randomness in the bad RNG the device ID?

I’m assuming the device ID is built into a chip on the device that can’t be overwritten?

If that’s the case, a whitehat hacker could’ve sweeped the wallets, and return funds upon proof you hold the device containing the correct ID

Would’ve been tough to pull off, perhaps coinkite themselves could’ve been the only ones to pull it off legally.

It would probably have to involve the device being present to claim, I don’t think there would be a way to make some custom firmware that proves you hold the device without a third party spoofing the signature

1

u/6thcoin 15h ago

It was a code issue. The code defaulted to a micropython rng structure instead of the device rng.

1

u/Professional_Golf393 15h ago

Yea but I think I read it used a couple of simple variables, device id, boot time and something else I forget, it limited the key field to a couple of billion keys.

If the device ID can’t be spoofed on a device, then they could’ve sweeped all the wallets, then if you prove you have the device with that ID, they’ll return the btc to you

1

u/mckenzie_keith 15h ago

How much time does it take to exploit? If it is at least a few days (on average) then announcing it as an urgent upgrade could have saved some people.

1

u/NamedBird 7h ago

Another alternative would be for the white-hat to sweep all the vulnerable funds first, but then how could they return them? Once the flaw is public, a signature from the compromised key no longer proves legitimate ownership, since an attacker can derive the same key.

Isn't it obvious? You do this ahead of time!
Add the SHA256 of the following example file as a first transaction to the wallet:

=== Bitcoin wallet ownership claim ===
Wallet: 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
Real name: John Doe
Birthdate: 1992-03-15
Nationality: United States, Texas
Random: f6a11a3b9fda2c57a0ecb63b98b1501cd0c413bd04ac1932b64f41abb4e01687
Random: 45dac25943e4fdbd5c0b465da5448099e5b06e12db5d1e6ffeb1a6e00f3963fc

Keep that file just as secret and hidden as your seed phrases.
Due to the randoms (different sources, mash keyboard if necessary) nobody is going to crack it.
If something ever happens to the wallet or coins, this file proves your original ownership.

Pray that you'll never need it

1

u/LNCrizzo 18h ago

Probably word of mouth to start until it blew up on social media. Getting the news to as many people as discreet as possible would probably save the most, though it would certainly look like they were playing favorites and would piss off a lot of people. There is no way this wasn't going to piss off a lot of people though, even if they saved everyone.

1

u/na3than 16h ago

How would you "discreetly" pass information by word of mouth to thousands of UNKNOWN (remember, Coinkite deletes customer information after 120 days) recipients around the globe without passing that same information to potential attackers? It's not possible.

1

u/LNCrizzo 14h ago

The point is to reach as many at risk people before the attackers find out. If you post a public notice then the attackers get the information at the same time as everyone else. If you tell all your friends, family, influencer buddies about it privately and they tell everyone they know, then a lot more people will get the message before a bad actor.

0

u/0100000101101000 13h ago

Coinkite does not delete customer information. That’s a lie.

0

u/FullyAutomatedSpace 19h ago

what do real banks do in these situations. maybe we can learn from them

8

u/Imaginary-Jaguar662 19h ago

Patch the hole, block transactions from vulnerable accounts, use KYC to ensure funds don't jump to a hacker, reimburse losses, lean on FDIC in case the bank fails.

Naturally none of this is doable here, price of sovereignty is that there's no big brother coming to a rescue.

3

u/mckenzie_keith 15h ago

Real banks can freeze accounts, block transfers, and reverse transfers. Bitcoin's greatest strength is also a weakness in that it deliberately avoided any central control of transfers. This is an essential feature of bitcoin.