COLDCARD Mk3 RNG flaw could lead to duplicate seed phrases; 4.5 million states crackable in seconds
AI Market Summary
A reported RNG weakness in certain COLDCARD Mk3 hardware wallets implies a drastically reduced seed-search space and a non-zero risk of duplicate mnemonics across devices, elevating key-compromise and custody risk. Even if constrained to a specific device cohort, the disclosure can pressure crypto risk sentiment by increasing perceived operational and counterparty risk around self-custody, potentially prompting precautionary fund movements and heightened scrutiny of wallet security practices.
Impact level
● Medium
Affected assets
BTC/USDT-0.64%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ME News reported that on Aug. 12 (UTC+8), Bitcoin News wrote on X that a new technical analysis by @KLoaec suggests some vulnerable COLDCARD Mk3 hardware wallets may draw from only about 4.5 million possible initial random-number-generator states. The analysis says those states can be exhaustively searched in roughly three seconds using a single RTX 4090 GPU. Even after factoring in additional uncertainties in how each wallet is initialized, the total search could still be completed in about 50 minutes on one high-end GPU.
The report also warns the weakness could cause separate devices to produce identical mnemonic seed phrases. Using an assumption of 30,000 Mk3 units in circulation, the analysis estimates around 120 pairs of devices could end up generating the same random-number stream. While described as a theoretical collision estimate, it points to a real risk of duplicate seed phrases across different devices. (Source: ODAILY)