Coldcard Exploit Highlights Risks of Software-Based Randomness
A recent exploit of the Coldcard Bitcoin hardware wallet has left millions in losses and raised questions about security in the industry. Charles Guillemet, CTO of Ledger, says the incident should serve as a warning for all hardware wallets, particularly those that rely on software-based random number generators.
The bug in the Coldcard wallet used a software fallback to generate recovery seeds instead of the device's own hardware random number generator, making private keys guessable and allowing thieves to steal user Bitcoin. To date, losses have reached roughly $130 million while other thefts remain under investigation.
Ledger says its own devices were not affected because they use independently certified hardware random number generators built directly into a secure element, with no software fallback path.
Guillemet notes that AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed. He emphasizes the importance of randomness in cryptography and advises users evaluating any hardware wallet to understand how it generates randomness and whether that process has been independently certified.