Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

1 hour ago 1



Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware. “Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin. Coldcard RNG flaw remained undetected for five yearsOn Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library. The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codeba...

Read Entire Article