Coldcard Flaw Exposes Hardware Wallet Security Gaps
The security of hardware wallets has been brought into question following a five-year flaw in Coldcard's seed-generation process. The vulnerability, which was discovered on Thursday, has allowed attackers to exploit weak seed phrases generated by affected devices.
Coldcard changed its seed-generation process in March 2021 as it integrated a new cryptographic library. However, the migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than the intended true random number generator (TRNG).
Kraken's chief security officer Nick Percoco has called for independent testing to verify that the approved source of randomness is actually used by production firmware. 'Consumers are asked to trust a manufacturer's implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,' he said.
As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin. Coldcard has halted all device shipments and destroyed remaining units containing the affected firmware.