Coldcard Flaw Drains $90M, Exposing Hardware Wallet Testing Gaps

Key Takeaways

Kraken’s Nick Percoco cites Coldcard’s seed-generation flaw as a wake-up call for independent hardware wallet testing. The bug, present since March 2021, drained nearly $90 million from over 4,500 addresses, highlighting a lack of end-to-end entropy v

Woofun AI reports that a critical seed-generation flaw within Coldcard hardware wallets has exposed systemic weaknesses in independent security testing, a gap highlighted by Kraken chief security officer Nick Percoco. The vulnerability, which persisted for five years, allowed attackers to exploit weak seed phrases, resulting in significant financial losses and raising urgent questions about the integrity of current verification protocols in the digital asset custody sector.

Percoco utilized an X post on Sunday to frame the incident as a necessary "wake-up call" for the entire hardware wallet manufacturing ecosystem. He argued that the industry must mandate independent testing to verify that the approved source of randomness is the specific component actually executed by production firmware. 'Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing," Percoco stated. This critique underscores a fundamental disconnect between theoretical security designs and the practical realities of firmware deployment, where manufacturers retain unchecked control over the execution of critical cryptographic functions.

Woofun AI data shows that the financial impact of this oversight has been severe, with an ongoing attack exploiting weak seed phrases generated by affected Coldcard devices. By Sunday, the breach had impacted over 4,500 addresses, draining nearly $90 million in Bitcoin. Coinkite, the company behind Coldcard, disclosed the software flaw on Thursday, revealing that the vulnerability had existed since March 2021. The issue originated when Coldcard integrated a new cryptographic library, inadvertently routing the wallet creation process to a weaker MicroPython generator that already existed in the codebase, rather than the intended true random number generator (TRNG).

Technical analysis of the failure reveals that the bulk of randomness on the COLDCARD was derived from a PRNG that Coinkite admitted was previously unknown to be present in the source code base. At the same time, the carefully crafted TRNG code written by the developer was active but utilized only by chance for less important tasks. This dual-state configuration allowed the vulnerability to remain undetected for years. Code reviews successfully confirmed the existence and functioning of Coldcard’s TRNG code, yet there was no mechanism to verify that this specific RNG was the one actually being called during seed generation. The presence of the correct code created a false sense of security, masking the operational reality of the weaker generator.

Percoco contrasted this failure with established practices in the broader security industry, citing NIST SP 800-90B, a US government standard for designing and validating physical true random number generators for cryptographic security. He also referenced BSI AIS-31, a similar standard created by the German Federal Office for Information Security, which mandates rigorous validation for secure elements. 'Hardware wallets have no equivalent process.

We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls," he noted. The payments industry requires independent lab testing for PIN entry devices, and the US government demands entropy source validation for cryptographic modules, suggesting that digital asset self-custody should not operate outside these rigorous frameworks.

In response to the confirmed vulnerability, Coldcard halted all device shipments on Thursday after identifying the flaw. The company destroyed all remaining units at its facilities that contained the affected firmware to prevent further distribution.

However, Coinkite advised users with affected devices not to dispose of them, stating that the hardware may become essential if funds are recovered. 'Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible," the company added, indicating a coordinated effort to trace the attackers and potentially mitigate the financial damage.

This incident reinforces the necessity of rigorous, independent security protocols in digital asset self-custody. The failure of Coldcard’s internal checks demonstrates that vendor-sponsored audits and theoretical code reviews are insufficient without end-to-end verification of entropy sources. As the industry matures, aligning hardware wallet standards with established security industry benchmarks will be critical to restoring consumer trust and preventing similar large-scale exploits.

Vote

Should hardware wallets require independent testing of entropy sources?

0 people voted

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions