Crypto
Home›Crypto›Regulation›Coldcard flaw highlights RNG testing gap in hardware w…
Coldcard flaw highlights RNG testing gap in hardware wallets
Kraken’s security chief said auditors failed to verify that the approved randomness source was actually called, after a Coldcard seed-generation issue left about 4,500 addresses affected and nearly $90 million in bitcoin drained.
Coldcard’s five-year seed-generation flaw has exposed weaknesses in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco, who said the problem went undetected because auditors confirmed an intended random number generator existed but did not verify it was being called in production firmware.
Percoco framed the incident as a “wake-up call” for hardware-wallet manufacturers, arguing that independent testing should confirm the approved entropy path is the one actually executing in real devices. He added that consumers are asked to trust a manufacturer’s implementation of the most critical function without independent verification of the randomness route.
The comments come as an attack believed to exploit weak seed phrases generated by affected Coldcard devices has left over 4,500 addresses impacted, draining nearly $90 million in bitcoin as of Sunday, Cointelegraph reported.
Cointelegraph said Coinkite disclosed a related software issue on Thursday, noting the flaw has existed since March 2021, when Coldcard changed its seed-generation process while integrating a new cryptographic library. Coinkite’s postmortem said wallet creation was inadvertently routed to a weaker MicroPython generator in the codebase instead of Coldcard’s intended true random number generator, allowing the vulnerability to slip past detection because the intended TRNG code was present but not reliably used.
Latest closeBitcoin $62,559.62 ▼0.3%