Coldcard Exploit Sparks Call for Improved Hardware Wallet Security
A recent exploit in the Coldcard Bitcoin hardware wallet has led Ledger to emphasize the importance of independently certified hardware random number generators for generating wallet recovery phrases.
The flaw, which allowed thieves to steal user Bitcoin worth approximately $130 million, was traced back to a March 2021 firmware build and used a software fallback instead of the device's hardware random number generator.
Ledger CTO Charles Guillemet noted that AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed. 'Cryptography is hard and implementing it securely is harder,' he said, adding that 'randomness has to come from physics, not a formula.'