Due to a critical low-entropy flaw discovered in Coldcard hardware wallets, linked to thefts beginning on July 30, Bitcoin owners are re-evaluating their security setups. Since firmware version 4.0.1, these devices used a pseudo-random number generator instead of the hardware random number generator, producing only 40 to 70 bits of entropy against the 128 bits required for a secure 12-word seed phrase. Attackers successfully brute-forced private keys and stole over $100 million worth of BTC. In response to this vulnerability, many users are turning to dice throws, a transparent and auditable physical entropy method, to generate their seed phrases securely.
Source: Read the original article

