All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard flaw highlights hardware wallet testing gap: Kraken security chief

Created at 3 Aug · 4:21 AM1 source↑ Market-relevant
IN SHORT

Kraken's chief security officer Nick Percoco stated that a five-year flaw in Coldcard hardware wallets reveals a gap in independent testing, urging manufacturers to verify that approved random number generators are actually used in production firmware.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

5 yearsduration of Coldcard flaw
March 2021when Coldcard changed seed-generation process
4,500+addresses impacted by exploit
$90 millionBitcoin drained by exploit

Who's Involved

Nick Percoco
Kraken chief security officer commenting on the flaw
Coldcard
Hardware wallet manufacturer with a five-year seed-generation flaw
Coinkite
Company that disclosed the Coldcard software flaw

↳ Why This Matters

This incident highlights critical security vulnerabilities in hardware wallets, potentially eroding user trust in self-custody solutions and underscoring the need for more rigorous, end-to-end testing protocols in the digital asset space.

Key facts

  • A five-year seed-generation flaw in Coldcard hardware wallets has been disclosed.
  • The vulnerability allowed wallet creation to use a weaker random number generator than intended.
  • The flaw has led to the draining of nearly $90 million in Bitcoin from over 4,500 addresses.
  • Kraken's chief security officer highlighted a gap in hardware wallet testing, stating that auditors verified the existence of random number generators but not their actual use.
  • Coldcard has halted shipments and destroyed affected devices.
  • A five-year-old software flaw in Coldcard hardware wallets has exposed a significant gap in the independent testing of such devices, according to Nick Percoco, chief security officer at Kraken. The vulnerability, which has been exploited to drain nearly $90 million in Bitcoin from over 4,500 addresses, arose when Coldcard integrated a new cryptographic library in March 2021, inadvertently routing seed generation to a weaker MicroPython generator instead of its intended true random number generator (TRNG).

    Percoco stated that the incident serves as a "wake-up call" for hardware wallet manufacturers, emphasizing the need for independent verification that the approved entropy source is the one actually executed by production firmware. He noted that while code reviews might confirm the presence of a TRNG, they often lack checks to ensure it's the one being called, a standard practice in other security-sensitive industries.

    Coldcard confirmed the vulnerability and has halted all device shipments, destroying remaining units with the affected firmware. Coinkite, the company that disclosed the flaw, advised users with affected devices to keep them, as they might be essential if funds are recovered. Law enforcement coordination is underway to identify those responsible for the exploit.

    Frequently asked questions

    A five-year flaw caused Coldcard devices to use a weaker MicroPython random number generator for seed phrases instead of the intended true random number generator.

    Nearly $90 million in Bitcoin has been drained from over 4,500 addresses impacted by the exploit.

    Kraken's security chief advocates for independent testing that verifies the actual execution of approved random number generators in production firmware, not just their existence.

    Coldcard has halted all device shipments and destroyed remaining units containing the affected firmware.

    What Happens Next

    01Coldcard to coordinate with law enforcement regarding the exploit.
    02Users with affected devices are advised to retain them.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence

    How It Developed

    A five-year software flaw in Coldcard hardware wallets was disclosed.
    The flaw routed wallet creation to a weaker MicroPython generator instead of the intended true random number generator.
    Over 4,500 addresses have been impacted, with nearly $90 million in Bitcoin drained.
    Kraken's chief security officer Nick Percoco called for improved independent testing of hardware wallets.
    Coldcard halted device shipments and destroyed affected units.
    Coinkite advised users with affected devices to retain them.

    Sources

    T1
    Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chiefThe five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called.Cointelegraph

    Related Stories

    Coldcard Hack Spurs Largest Sub-1 BTC Move Since FTX Collapse
    2 Aug · 8:21 AM
    Coldcard exploit prompts bitcoin holders to move funds to exchanges
    2 Aug · 12:11 PM
    Perpetual futures: governance key when expiry disappears
    3 Aug · 3:40 AM
    South Korean stablecoin outflows top $367M in June
    3 Aug · 4:21 AM
    BNB Chain Pursues Legal Action Over Unauthorized Memecoin Launch
    2 Aug · 11:36 AM