Coldcard Flaw Exposes Hardware Wallet Testing Gap: Kraken CSO

A five-year-old software flaw in Coldcard hardware wallets led to the theft of approximately $89 million in Bitcoin. Kraken's Chief Security Officer, Nick Percoco, stated that this incident serves as a "wake-up call" for the hardware wallet industry, emphasizing the need for independent audits to verify the randomness sources used in seed phrase generation.

Borsaya Newsroom
|
Cointelegraph
|
August 3, 2026 at 04:09 AM
|
4 min read
|

A critical five-year-old firmware vulnerability in Coldcard hardware wallets, a prominent name in the cryptocurrency market, has resulted in the theft of an estimated $89 million worth of Bitcoin (BTC) from thousands of wallets. This security lapse has highlighted a significant gap in how hardware wallets' random number generators (RNGs) are tested for seed phrase creation, prompting renewed calls for rigorous independent audits within the industry.

The flaw, stemming from a software change in March 2021 during a firmware migration and cryptographic library integration by Canadian manufacturer Coinkite, inadvertently redirected wallet creation to a weaker, deterministic MicroPython pseudo-random number generator (PRNG) instead of Coldcard's intended hardware-backed true random number generator (TRNG). This compromised the randomness of generated wallet seeds, making them significantly more predictable and enabling attackers to reconstruct private keys offline.

The vulnerability remained undetected for five years primarily because auditors verified the *existence* of the intended TRNG but failed to confirm that it was actually *being invoked* for seed generation. Since the MicroPython PRNG was present in the codebase, and a check for whether the hardware RNG macro was *defined* passed (regardless of whether it was *enabled* for seed generation), the system silently defaulted to the weaker method. The issue came to light following reports of lost funds from Coldcard users, prompting investigations by Galaxy Research and Block's Bitcoin Engineering and Security teams.

The attacks commenced in multiple waves starting July 30, 2026. According to analyses by Galaxy Research, approximately 1,367 BTC, valued at nearly $89 million, has been stolen from over 4,500 addresses to date. Attackers reportedly prioritized high-value wallets and evolved their tactics to evade tracing. This incident underscores that while offline storage is crucial for crypto assets, a foundational weakness in the seed phrase generation can render such protections ineffective.

Nick Percoco, Chief Security Officer at Kraken, emphasized that this incident should serve as a "wake-up call" for hardware wallet manufacturers. He advocated for independent testing of production firmware to verify that the approved entropy sources are indeed the ones utilized. Percoco highlighted that the U.S. government does not approve cryptographic modules without validating their entropy sources, arguing that digital asset self-custody should not be an exception. In response, Coinkite confirmed the vulnerability, halted shipments of affected devices, and destroyed existing inventory. The company advised affected users to generate new seed phrases on patched firmware and transfer their assets.

Analysts and industry experts anticipate that such events will accelerate the adoption of stricter security protocols and independent audit standards within the hardware wallet industry. Some reports also suggest that AI-powered auditing tools, such as Claude Code, were able to quickly identify this flaw, indicating a potential future role for these technologies in uncovering security vulnerabilities. Users are strongly advised to ensure their firmware is updated, generate seed phrases carefully, and remain vigilant against potential security compromises.

Related Symbols

Share
9

₿ Want to ride this crypto move?

Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.

Comments (0)

0/1000

No comments yet. Be the first to comment!

Coldcard Flaw Exposes Hardware Wallet Testing Gap: Kraken CSO | Borsaya.com