Coldcard Bug Exposes Flaw in Hardware Wallet Industry
A critical bug in Coldcard's random number generator remained undetected for five years, compromising nearly $90 million in Bitcoin. The flaw was introduced in March 2021 during the integration of a new cryptographic library and redirected the wallet creation process toward a MicroPython pseudorandom generator.
The issue went unnoticed because auditors verified that the true random number generator (TRNG) existed and functioned within the system, but not that it was actually used in production. Kraken's chief security officer noted that 'consumers must trust the manufacturer's implementation of the system's most critical function, with no independent verification that the approved entropy path is the one actually executed.'
The absence of end-to-end verification in the hardware wallet industry is a major concern, as this type of verification is already mandatory in other industries such as government and finance. Coinkite has halted all device shipments and destroyed units with affected firmware, but advises users not to discard compromised devices.