Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco.
In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco.
His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin.
Coldcard RNG flaw remained undetected for five years
On Thursday,…