As I’m sure you’ve heard: a firmware bug traced to a March 2021 Coldcard build routed part of seed generation through a software RNG instead of the device’s hardware one. The seeds came out with far less entropy than advertised: enough that private keys could be reconstructed offline, without ever touching the device. Roughly 1,367 BTC ( approx $89m) drained from over 4,000 addresses in waves starting the 30th of July.

Nobody fully eliminates custody risk, because of what happened, I imagine people are looking to move from self custody to other alternatives:

Regulated wrapper (IBIT, ETHA) – you hold a claim on a trust, not coins. No seed, no firmware. Also no on-chain use, market hours only, ~0.25%/yr taken out of the BTC backing each share, and a position fully visible to your broker and tax authority. Fails via custodian or issuer risk. Private Bank custody – held alongside the rest of your wealth, with the reporting and estate planning that comes with it. Fails via institution risk and, mostly, access: getting onboarded is the hard part, many Swiss private banks do not offer crypto custody, recently some have added this feature. Self-custody – you’re the counterparty, and “you” includes a firmware supply chain you can’t audit. Coldcard is one of the more paranoid vendors in the space and still shipped a bad entropy path for five years. Fails via firmware/supply chain, key loss, inheritance, coercion, your own error.

Are you guys going to move from self custody? If so which of these alternatives would you choose?

Check Coinkite’s official website for affected models and firmware. General information, not investment, legal, or tax advice.

submitted by /u/alt-co [link] [comments]r/CryptoCurrencyRead More

You might also be interested in reading Technically my website could make me $80 billion. It won’t. But it could. It tries to brute force guess Satoshi Nakamoto Wallet..