Coldcard exploit sparks call for independent audits: Kraken CSO

1 hour ago 1



Coldcard’s five-year seed-generation flaw has renewed calls for independent testing of hardware wallet firmware after suspected attacks have drained nearly $90 million worth of Bitcoin from thousands of wallets. Summary Kraken’s chief security officer has called for independent testing of hardware wallet seed generation after the Coldcard security flaw. Suspected attacks have drained nearly $90 million in Bitcoin, with Galaxy Research tracking more than 5,200 potential victim addresses. Coinkite has released fixed firmware but says affected users must create new seed phrases because updates cannot repair existing wallets. Security researchers traced the issue to a firmware error that used a weaker random number generator during wallet creation. Kraken chief security officer Nick Percoco said in a post on X on Sunday that the incident should serve as a warning for the hardware wallet industry, arguing that manufacturers should not be the only parties verifying how wallet seed phrases are generated. He said production firmware should undergo independent testing to confirm that the approved source of randomness is the one actually used when creating wallet secrets. According to Galaxy...

Read Entire Article