Coldcard Flaw Exposes Hardware Wallet Testing Gap
A recent flaw in Coldcard's seed-generation process has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco.
The incident involved a five-year-old vulnerability that was only recently discovered and is believed to have been exploited in over 4,500 addresses, draining nearly $90 million in Bitcoin.
Percoco argued that the presence of a true random number generator (TRNG) code did not guarantee its use, as it was possible for production firmware to call on a weaker pseudo-random number generator (PRNG) instead.
The Coinkite team acknowledged that the TRNG code was present in the source code base but was not being used for wallet creation due to an unintentional routing issue. This highlights a lack of independent testing and verification in the hardware wallet industry, with Percoco calling for end-to-end verification of entropy sources.
Coldcard has since halted all device shipments and destroyed affected units containing the compromised firmware, but Coinkite advises users not to dispose of their devices in case recovered funds are needed.