A five-year-old software flaw in Coldcard hardware wallets has exposed a significant gap in the independent testing of such devices, according to Nick Percoco, chief security officer at Kraken. The vulnerability, which has been exploited to drain nearly $90 million in Bitcoin from over 4,500 addresses, arose when Coldcard integrated a new cryptographic library in March 2021, inadvertently routing seed generation to a weaker MicroPython generator instead of its intended true random number generator (TRNG).
Percoco stated that the incident serves as a "wake-up call" for hardware wallet manufacturers, emphasizing the need for independent verification that the approved entropy source is the one actually executed by production firmware. He noted that while code reviews might confirm the presence of a TRNG, they often lack checks to ensure it's the one being called, a standard practice in other security-sensitive industries.
Coldcard confirmed the vulnerability and has halted all device shipments, destroying remaining units with the affected firmware. Coinkite, the company that disclosed the flaw, advised users with affected devices to keep them, as they might be essential if funds are recovered. Law enforcement coordination is underway to identify those responsible for the exploit.