به Nostr بپیوندید
2026-08-04 03:41:59 CEST

Brie on Nostr: The entropy bug in the cc wallets was, quite literally, trivial to find There was a 0 ...

The entropy bug in the cc wallets was, quite literally, trivial to find

There was a 0 (where there should not have been) that fixed compilation errors… this would have been obvious to ANY low level hardware dev that reviewed this

It was literally defined to NOT call THE MOST IMPORTANT PIECE OF SOURCE CODE AND IT WAS NOT EVEN CONFUSING TO READ

No one needed a super high powered Chinese LLM pointed at it

This is like the equivalent of hiring a multilingual person that specializes in interpreting ancient heiroglyphics to come to your house and read your 5 year old “Jack and Jill went up the hill”
There have been reports that cold card wallets were being drained going back years and reports were made.

In other words that there could already have been bad actors taking funds for years or my suspicion is that because there was such low entropy that two separate users could have actually made the same single sig seed.

That someone could have spent someone elses sats without even knowing why.

Going fuether in theory this could mean in an edge case That today one person's coldcard wallet may be being cleared out by another cold card user trying to save themselves 🤯

Some disagree