
Kraken CISO says Coldcard's five-year seed-generation flaw slipped past auditors who verified the intended RNG existed. No check confirmed what production firmware called. $90M in Bitcoin drained.
Alpha Score of 67 reflects moderate overall profile with strong momentum, strong value, weak quality, moderate sentiment.
Auditors verified that Coldcard's intended true random number generator existed in the codebase. No check confirmed that production firmware actually called it. That gap allowed a seed-generation flaw to go undetected for five years, according to Kraken chief security officer Nick Percoco.
In an X post Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers. He called for independent testing that verifies the approved source of randomness is the one executing, not just present.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” Percoco wrote.
His comments came as an ongoing exploit believed to target weak seed phrases from affected Coldcard devices has drained nearly $90 million in Bitcoin across more than 4,500 addresses as of Sunday.
Coinkite disclosed Thursday that a software flaw had been present since March 2021, when Coldcard changed its seed-generation process during integration of a new cryptographic library. The migration routed wallet creation to a weaker MicroPython generator that existed in the codebase, bypassing Coldcard's intended true random number generator.
“The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, just by chance, and only for less important things.”
The presence of the intended TRNG code allowed the vulnerability to remain undetected through code reviews. Reviewers would confirm the TRNG existed and functioned correctly. No test verified that production firmware actually called it rather than the weaker alternative.
Such end-to-end checks are standard elsewhere in security, Percoco said. He cited NIST SP 800-90B, a US government standard for validating physical true random number generators, and BSI AIS-31, a similar German standard.
“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said.
“The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception.”
Coldcard said Sunday it halted all device shipments after confirming the vulnerability Thursday and destroyed all remaining units at its facilities containing the affected firmware. Coinkite advised users with affected devices not to dispose of them, saying they “may become essential if funds are recovered.”
“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible,” Coinkite said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.