
Kraken CSO says Coldcard's seed-generation flaw shows why hardware wallet firmware needs independent testing. Galaxy tracks 1,800+ BTC swept from 5,200+ addresses across four attack waves.
Alpha Score of 58 reflects moderate overall profile with moderate momentum, strong value, weak quality. Based on 3 of 4 signals — score is capped at 90 until remaining data ingests.
Kraken chief security officer Nick Percoco said the Coldcard seed-generation flaw should push the hardware wallet industry toward independent firmware testing, arguing that manufacturers should not be the only party verifying how wallet secrets are created.
In an X post Sunday, Percoco said production firmware needs third-party confirmation that the approved randomness source is the one actually used when generating wallet seeds.
The call follows Coinkite's disclosure Thursday of a vulnerability dating to March 2021. A firmware migration integrating a new cryptographic library accidentally replaced Coldcard's hardware-backed true random number generator with a weaker deterministic pseudo-random generator from MicroPython. The intended generator stayed active elsewhere in the firmware, so code reviews verified its presence without revealing that wallet creation relied on a different entropy source.
Coinkite said it was unaware the MicroPython generator existed in the relevant code path until the investigation.
Block's Bitcoin engineering and security team independently reached the same conclusion. Block said it had not completed full empirical testing of every device but decided to disclose its findings because reports of active theft had already emerged.
Galaxy Research's blockchain analysis estimates that suspected attackers have swept more than 1,800 BTC from over 5,200 potential victim addresses across four observed attack waves. The firm stressed those are on-chain estimates, not confirmed losses. Coinkite has not verified every affected wallet, and blockchain data alone cannot determine whether a single actor carried out all the attacks.
Alex Thorn, head of research at Galaxy, identified a suspected fourth coordinated wave on Aug. 3, bringing the firm's observed total to about 1,815.75 BTC across 5,294 potential addresses if none overlap. Thorn described the wallets as "likely Coldcard victims" and emphasized the figures come from blockchain analysis, not confirmed device records or law enforcement findings.
Attack activity reached 13.8 wallet sweeps per block during the latest wave, Galaxy reported, compared with a baseline of 0.3 sweeps per block before the incident. Most victim balances were sent to newly created addresses rather than a single collection wallet. Some funds had already moved through second-hop transactions, making the stolen Bitcoin harder to trace.
Galaxy noted that users whose stolen funds remain in unconfirmed transactions may still have a narrow opportunity to broadcast a higher-fee replacement transaction before miners confirm the original transfer. Replace-by-Fee can only be attempted while the transaction remains unconfirmed and does not guarantee recovery even when the legitimate owner still controls the affected keys, the firm said.
Percoco argued that hardware wallet certification has overlooked one of the most important parts of wallet security. Users currently have to trust that manufacturers correctly implement seed generation because no independent process verifies that production firmware actually calls the approved entropy source. Existing certifications, including Common Criteria evaluations for secure elements, CSPN reviews and vendor-sponsored audits, do not systematically validate that relationship, according to Percoco.
To illustrate the gap, he pointed to NIST SP 800-90B, the U.S. standard for designing and validating true random-number generators used in cryptographic systems, along with Germany's BSI AIS-31 framework. Comparable end-to-end verification does not currently exist for hardware wallets, he argued.
Percoco also compared the sector with payment security. PIN entry devices cannot be shipped without independent laboratory testing, while U.S. government cryptographic modules require entropy source validation before approval.
Coinkite estimates that seeds created on affected Mk2 and Mk3 devices contain about 40 bits of effective entropy. Affected Mk4, Mk5 and Q models contain about 72 bits instead of the intended 128 bits.
The company halted all shipments after confirming the vulnerability and destroyed every remaining device in its facilities containing the affected firmware. Coinkite advised customers not to discard affected devices because they may become important if stolen funds are eventually recovered through legal proceedings. The company's legal team will coordinate with law enforcement agencies in multiple jurisdictions where appropriate.
Firmware updates have been released for every affected model: version 4.2.0 for Mk2 and Mk3, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for Coldcard Q, and versions 6.6.0X and 6.6.0QX for Edge releases. Installing updated firmware only fixes future wallet creation. It does not strengthen seed phrases generated before the patch.
Users covered by the advisory are being instructed to generate entirely new seed phrases after updating their devices, verify a receiving address, send a small test transaction, and migrate the remaining balance only after confirming the transfer succeeded.
Coinkite said wallets created using at least 50 fair, private dice rolls are not considered exposed by the random-number-generation flaw alone. A strong and unique BIP-39 passphrase provides another layer of protection but does not remove the weakness from an already affected seed, so migration remains the recommended course of action.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.