Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested, according to Kraken's chief security officer. The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impactin…
Intelligence analysis by Llama

A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested, according to Kraken's chief security officer. The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impacting over 4,500 addresses and draining nearly $90 million in Bitcoin.
Imagine you have a special box that helps you keep your money safe. But what if someone could trick the box into giving them the combination to open it? That's what happened with some special boxes called Coldcard. A group of people found a way to make the boxes give them the wrong combination, and they were able to take a lot of money. This is a big problem because people trust these boxes to keep their money safe.
Analysis
A $60B Vote of Confidence
The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called. This highlights a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
Why Cursor?
Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin.
The Road Ahead
The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.
Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. “The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco.
Key points
- A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested.
- The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impacting over 4,500 addresses and draining nearly $90 million in Bitcoin.
- Kraken's chief security officer is calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
- The industry has no equivalent process for testing and verifying hardware wallets, unlike the payments industry and the US government.
If the hardware wallet industry takes steps to improve testing and verification, it could lead to more secure and trustworthy products. This could give consumers more confidence in using digital assets for self-custody.
If the industry does not take action to address the testing gap, it could lead to more vulnerabilities and attacks on hardware wallets. This could result in significant financial losses for consumers and damage to the reputation of the industry.



