Key facts
- A flaw existed in Coldcard hardware wallets for five years.
- Kraken's chief security officer Nick Percoco highlighted the flaw.
- The flaw reveals a gap in independent testing of hardware wallets.
- Manufacturers are urged to verify the use of approved random number generators in production firmware.
- Hardware wallets are used to store sensitive cryptocurrency assets.
A flaw present for five years in Coldcard hardware wallets has been brought to light, revealing a significant gap in the independent testing procedures for these security devices. Nick Percoco, the chief security officer at Kraken, stated that this vulnerability demonstrates a need for hardware wallet manufacturers to implement more robust testing protocols. Specifically, Percoco urged manufacturers to verify that the random number generators (RNGs) approved for use are indeed present and functional in the production firmware of their devices. Hardware wallets are critical for securing cryptocurrency assets, making the integrity of their random number generation processes paramount for preventing potential exploits and ensuring the safety of user funds. The extended period the flaw went undetected suggests a broader issue within the industry regarding the thoroughness of security audits and quality assurance for hardware wallet firmware.