Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Coldcard discovered a five-year-old vulnerability in its hardware wallet’s seed-generation method that routed seed creation to a weaker random number generator rather than the intended true random number generator. Kraken’s chief security officer, Nick Percoco, highlighted this flaw as evidence of a wider gap in independent testing of hardware wallets, with no mandatory verification that the validated entropy source is the one used in production firmware. The flaw has reportedly led to attacks draining nearly $90 million in Bitcoin from over 4,500 addresses.
Why it matters
According to Kraken’s security chief, this incident “should be a wake-up call” for hardware-wallet manufacturers, emphasizing the need for independent and end-to-end testing of entropy sources to ensure cryptographic security. Percoco contrasts the lax standards in digital asset self-custody hardware wallet testing with stricter verification practices in other security industries such as payments and government cryptographic modules. This development underscores a potential systemic weakness in hardware wallet security assurance.
Key context
The vulnerability stemmed from a March 2021 software update integrating a new cryptographic library, which accidentally defaulted wallet creation to a weaker MicroPython pseudorandom number generator instead of the intended true random number generator. Code reviews had confirmed the existence of the strong TRNG code but did not verify its actual execution. This allowed the flaw to remain unnoticed for five years. The security community references standards like NIST SP 800-90B and BSI AIS-31 for entropy source testing, but such rigorous independent verification does not presently exist in hardware wallet production.
Key numbers and entities
Key entities include Kraken and its chief security officer Nick Percoco, Coldcard and its parent company Coinkite. Over 4,500 Bitcoin addresses have been affected, with nearly $90 million drained. The flaw existed since March 2021 and was confirmed and publicly disclosed in early August 2023. The standards cited as examples include NIST SP 800-90B and BSI AIS-31.
What remains unclear
The source does not detail the exact scope of affected Coldcard models beyond those shipped since March 2021 or the full potential scale of losses. It also remains uncertain how and when attackers first exploited the flaw. Coldcard has halted shipments and destroyed remaining affected units but advises affected users to retain their devices for potential fund recovery efforts. The coordination with law enforcement is ongoing, with no further updates on the investigation’s progress.