Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
Coldcard’s seed-generation bug has highlighted a wider testing gap in hardware wallets, according to Kraken CSO Nick Percoco. He said users are forced to trust manufacturers’ entropy implementation without independent proof that the approved randomness source is actually used in production firmware. The flaw, disclosed by Coinkite, had existed since March 2021. During a cryptographic library migration, wallet seed creation was inadvertently routed to a weaker MicroPython PRNG instead of the intended TRNG. Because the TRNG code still existed and functioned for other uses, the bug escaped detection for years. The issue is believed to have enabled an ongoing attack using weak seed phrases, affecting more than 4,500 addresses and draining nearly $90 million in bitcoin. Coinkite has halted shipments and destroyed affected inventory. Percoco argued hardware wallets should face independent entropy-source validation similar to standards used in payments, government crypto modules, and secure random-number generation testing.
