Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief img1
Spread the love

Written by Felix Ngstaff editorReviewed by Yohan Yunstaff editor

Written by Felix Ngstaff editor

Reviewed by Yohan Yunstaff editor

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

Latest NewsPublishedAug 3, 2026

A Major Flaw in Coldcard Hardware Wallets Exposes a Gap in Testing

The recent discovery of a five-year-old flaw in Coldcard hardware wallets has highlighted a significant weakness in the testing process for these devices. According to Nick Percoco, chief security officer at Kraken, this incident should serve as a wake-up call for hardware wallet manufacturers to improve their independent testing procedures. The flaw, which affected the seed-generation process, went undetected for years because auditors only verified the existence of the intended random number generator, not whether it was actually being used.

This vulnerability has already led to a significant loss of Bitcoin, with over 4,500 addresses impacted and nearly $90 million drained. The attack exploited weak seed phrases generated by affected Coldcard devices, which were caused by a software flaw introduced in March 2021. To earn and protect your crypto assets, it’s essential to use a reliable and secure platform like EcoPool, which offers Passive Income opportunities through its Cloud Rewards system.

Improving Testing Procedures for Hardware Wallets

Percoco emphasizes the need for independent testing to verify that the approved source of randomness is the one actually used by production firmware. This is a standard practice in the rest of the security industry, but it’s currently lacking in the hardware wallet sector. By using a platform like EcoPool, you can ensure that your Coin is secure and that you’re earning a Passive Income through a trusted and reliable system.

The EcoPool network offers a Green Crypto solution that allows you to earn $ECP while contributing to a more sustainable and environmentally friendly ecosystem. By joining the EcoPool community, you can take advantage of its Cloud Rewards system and start earning a Passive Income today.

Conclusion and Call to Action

In conclusion, the recent flaw in Coldcard hardware wallets highlights the need for improved testing procedures in the industry. To ensure the security of your Coin and start earning a Passive Income, consider using a reliable platform like EcoPool. Download the EcoPool app to start earning $ECP and contributing to a more sustainable crypto ecosystem. By joining the EcoPool network, you can take the first step towards a more secure and profitable crypto experience EcoPool

Coldcard RNG flaw remained undetected for five years

On Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library. 

The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG). 

“The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”

The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. 

Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.

“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. 

“The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco. 

Related: Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s Thorn

Coldcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities containing the affected firmware. 

However, Coinkite has advised users with affected devices not to dispose of them as “it may become essential if funds are recovered.”

“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.” 

Related: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Hardware Wallet
  • Hacks
  • Kraken
  • Scams & Cybercrime

More on the subject

Apple faces lawsuit over alleged $1.8M Bitcoin wallet app losses



Jul 28, 2026

Helen Partz

News Brief

Brazilian police bust cocaine traffickers in crypto-linked transnational probe



Jul 27, 2026

Adrian Zmudzinski

News Brief

Robinhood CEO’s X account hacked in apparent memecoin scam



Jul 23, 2026

Sam Bourgi

News Brief

Apple faces lawsuit over alleged $1.8M Bitcoin wallet app losses



Jul 28, 2026

Helen Partz

News Brief

Brazilian police bust cocaine traffickers in crypto-linked transnational probe



Jul 27, 2026

Adrian Zmudzinski

News Brief

Robinhood CEO’s X account hacked in apparent memecoin scam



Jul 23, 2026

Sam Bourgi

News Brief


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these