Coldcard Flaw Exposes Hardware Wallet Testing Gap
A hardware wallet testing gap has been exposed after a five-year flaw in Coldcard's seed-generation process was revealed. The vulnerability, which existed since March 2021, allowed affected devices to generate weak seed phrases, leaving users open to exploitation.
Kraken's chief security officer, Nick Percoco, called the incident a 'wake-up call' for hardware-wallet makers and highlighted the need for independent testing to verify that approved sources of randomness are being used. He noted that consumers trust manufacturers to implement critical functions in their systems without independent verification.
The flaw was discovered on Thursday by Coinkite, which found that Coldcard's migration to a new cryptographic library inadvertently routed wallet creation to a weaker random number generator. As a result, nearly $90 million in Bitcoin has been drained from over 4,500 addresses.