Coldcard Flaw Spurs Calls for Independent Testing of Hardware Wallet Firmware
A recent Coldcard security flaw has led to nearly $90 million in Bitcoin losses and sparked calls for independent testing of hardware wallet firmware. Kraken's chief security officer, Nick Percoco, argues that manufacturers should not be the only parties verifying how wallet seed phrases are generated.
The issue dates back to March 2021 when Coinkite migrated part of its firmware while integrating a new cryptographic library. Instead of using the intended hardware-backed true random number generator to create wallet seeds, the updated firmware accidentally called a weaker deterministic pseudo-random generator provided by MicroPython.
Coldcard users are advised to generate entirely new seed phrases after updating their devices, as installing the fixed firmware only fixes future wallet creation and does not strengthen seed phrases generated before the patch. According to Coinkite, wallets created using at least 50 fair, private dice rolls are not considered exposed by the random-number-generation flaw alone.