Coldcard Flaw Exposes Hardware Wallet Testing Gap
The recent Coldcard vulnerability has exposed a critical weakness in how hardware wallets are tested. According to Kraken's chief security officer, Nick Percoco, this incident is not just a bug but a fundamental flaw in the testing process.
Coldcard's five-year-old seed-generation flaw was revealed after an ongoing exploit campaign targeted weak seed phrases generated by affected devices. As of Sunday, more than 4,500 addresses were reported impacted, with losses estimated at nearly $90 million in Bitcoin.
The issue stems from a process change made in March 2021 when Coldcard integrated a new cryptographic library. Coinkite's postmortem describes how the company inadvertently routed wallet creation through a weaker MicroPython generator instead of using its intended true random number generator (TRNG).
Percoco pointed to established standards like NIST SP 800-90B and BSI AIS-31 as models for validating entropy sources. He argued that current practices in the hardware-wallet ecosystem lack end-to-end validation, allowing critical cryptographic expectations to be silently violated.