Loading market data...
Back to Feed
CRYPTO NEWS

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$90 million

Summary

Coldcard discovered a five-year-old vulnerability in its hardware wallet’s seed-generation method that routed seed creation to a weaker random number generator rather than the intended true random number generator. Kraken’s chief security officer, Nick Percoco, highlighted this flaw as evidence of a wider gap in independent testing of hardware wallets, with no mandatory verification that the validated entropy source is the one used in production firmware. The flaw has reportedly led to attacks draining nearly $90 million in Bitcoin from over 4,500 addresses.

Why it matters

According to Kraken’s security chief, this incident “should be a wake-up call” for hardware-wallet manufacturers, emphasizing the need for independent and end-to-end testing of entropy sources to ensure cryptographic security. Percoco contrasts the lax standards in digital asset self-custody hardware wallet testing with stricter verification practices in other security industries such as payments and government cryptographic modules. This development underscores a potential systemic weakness in hardware wallet security assurance.

Key context

The vulnerability stemmed from a March 2021 software update integrating a new cryptographic library, which accidentally defaulted wallet creation to a weaker MicroPython pseudorandom number generator instead of the intended true random number generator. Code reviews had confirmed the existence of the strong TRNG code but did not verify its actual execution. This allowed the flaw to remain unnoticed for five years. The security community references standards like NIST SP 800-90B and BSI AIS-31 for entropy source testing, but such rigorous independent verification does not presently exist in hardware wallet production.

Key numbers and entities

Key entities include Kraken and its chief security officer Nick Percoco, Coldcard and its parent company Coinkite. Over 4,500 Bitcoin addresses have been affected, with nearly $90 million drained. The flaw existed since March 2021 and was confirmed and publicly disclosed in early August 2023. The standards cited as examples include NIST SP 800-90B and BSI AIS-31.

What remains unclear

The source does not detail the exact scope of affected Coldcard models beyond those shipped since March 2021 or the full potential scale of losses. It also remains uncertain how and when attackers first exploited the flaw. Coldcard has halted shipments and destroyed remaining affected units but advises affected users to retain their devices for potential fund recovery efforts. The coordination with law enforcement is ongoing, with no further updates on the investigation’s progress.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]