Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Bitcoin Crypto News

    Coldcard’s 5-Year Flaw Shows Hardware Wallet Testing Gaps, Kraken Chief

    21 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Coldcard’s 5-Year Flaw Shows Hardware Wallet Testing Gaps, Kraken Chief
    Coldcard’s 5-Year Flaw Shows Hardware Wallet Testing Gaps, Kraken Chief

    Coldcard’s five-year seed-generation issue has turned into a wider debate over how hardware wallets are independently verified, according to Kraken’s chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should prompt makers of self-custody devices to require end-to-end checks that confirm the randomness source reviewed in testing is the same one actually executed by production firmware.

    The comments arrive amid an ongoing exploit believed to target vulnerable Coldcard devices by abusing weak seed phrases. By Sunday, more than 4,500 addresses had reportedly been affected, with losses estimated at nearly $90 million in Bitcoin, according to Cointelegraph’s reporting linked in the original article.

    Key takeaways

    • Kraken’s Nick Percoco argues hardware wallet certification should include verification that the approved entropy path is what production firmware uses in practice.
    • Coldcard’s RNG-related flaw allegedly persisted for years after a seed-generation change introduced an unintended reliance on a weaker generator.
    • Percoco cited existing standards used in the broader security and payments industries—such as NIST SP 800-90B and BSI AIS-31—as models for what should be standard for crypto self-custody.
    • Coinkite says affected firmware has been halted in shipments and that remaining units containing the vulnerable code were destroyed, while it advised users not to discard certain devices.

    A hardware wallet “wake-up call” for entropy verification

    Percoco’s central point is about trust boundaries. Hardware wallet users are asked to rely on a manufacturer’s implementation of the randomness function that ultimately underpins seed phrase generation—yet, he said, there is often no independent method to confirm that the verified randomness source is the one the device will actually call in production.

    “Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” Percoco wrote in his Sunday post.

    He described this gap as an industry-wide weakness rather than a one-off mistake, noting that while some certifications exist for hardware components and secure elements, they do not “systematically force end-to-end verification” of the entropy source through to production code execution.

    Percoco contrasted the crypto self-custody space with practices in other sectors. He pointed to the payments industry’s use of independent lab testing for devices that collect sensitive inputs, and to government expectations in the US around cryptographic module validation and entropy source testing.

    How the Coldcard flaw allegedly slipped through

    According to the original reporting, the vulnerability traces back to a software change disclosed by Coinkite. The company said the relevant issue has existed since March 2021, when Coldcard altered its seed-generation process as it integrated a new cryptographic library.

    The update, per Coinkite’s postmortem referenced in the article, unintentionally routed wallet creation to a weaker MicroPython generator already present in the codebase. Coinkite’s explanation indicated that Coldcard’s intended true random number generator (TRNG) code existed and could be present and functioning, but was not reliably the one used for the core randomness needed for seeds.

    In other words, reviewers could verify that the TRNG code was present and worked—but, without a mechanism to ensure the device actually called that TRNG during seed generation, the system could still produce outcomes derived from a different generator than intended.

    The practical consequence is that seed phrases generated under the affected conditions may become more predictable than they should be. That predictive weakness is widely viewed by the security community as especially dangerous in wallet designs because compromised seeds can enable theft without needing to break keys directly.

    Attack fallout and what’s changing for users

    The ongoing exploit believed to target weak seed phrases generated by affected Coldcard devices has already resulted in extensive on-chain activity. As of Sunday, Cointelegraph’s figures cited in the original article reported over 4,500 impacted addresses and losses approaching $90 million in Bitcoin.

    Coldcard (Coinkite) said it has halted all device shipments since confirming the vulnerability on Thursday. It also stated it destroyed remaining units at its facilities that contained the affected firmware.

    At the same time, the company advised users with affected devices not to dispose of them immediately, saying doing so might become “essential if funds are recovered.” The company also indicated its legal team would coordinate with law enforcement across multiple jurisdictions to support efforts identifying those responsible.

    For affected owners, the new information underscores a key operational point: device handling decisions may need to be aligned with recovery processes rather than treated as purely disposal or cleanup tasks. While that doesn’t eliminate the security risk of continuing exposure, it suggests an active incident-response posture where retaining evidence or workable hardware could matter.

    Standards exist—what’s missing is enforcement

    Percoco’s critique points to a tension that many investors and builders may recognize: crypto security often emphasizes reviewing code paths and cryptographic primitives, but not always the end-to-end behavior under production conditions—especially the specific entropy source used at runtime.

    He referenced NIST SP 800-90B, which sets requirements for designing, testing and validating physical true random number generators for cryptographic security, and BSI AIS-31, a similar standard from Germany’s Federal Office for Information Security. In his view, such frameworks make it more difficult for systems to “pass review” without proving that the approved randomness pathway is actually used for critical operations.

    Whether regulators and certifiers will adapt those expectations to consumer self-custody products remains uncertain. However, the Coldcard case demonstrates why the distinction matters: even when a correct TRNG implementation exists in the codebase, the seed-generation workflow can still be compromised if production firmware routes randomness differently than what independent review assumes.

    Next, investors and users should watch for two things: clarification from Coinkite on exactly how to identify which devices/firmware are affected and what remediation steps best reduce future risk, and whether independent testers or certifiers move toward stronger “entropy source at runtime” validation—an area Percoco argues should not remain optional in digital asset custody.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Coldcard Exploit Drives Bitcoin Outflows As “hodlers” Consolidate—aug 2 Digest

    Coldcard exploit drives Bitcoin outflows as “hodlers” consolidate—Aug 2 digest

    4 hours ago
    Strategy Maintains 12% Strc Preferred Dividend Despite Below-Par Price

    Strategy Maintains 12% STRC Preferred Dividend Despite Below-Par Price

    11 hours ago
    Strategy Maintains 12% Preferred Strc Dividend Despite Discount

    Strategy Maintains 12% Preferred STRC Dividend Despite Discount

    12 hours ago
    Coldcard Hack Fallout Widens As Bitcoin Losses Hit $88.6m

    Coldcard Hack Fallout Widens as Bitcoin Losses Hit $88.6M

    16 hours ago
    Trump Media Moves 2,628 Btc To Crypto.com, Wallet Drops To 4,261

    Trump Media Moves 2,628 BTC to Crypto.com, Wallet Drops to 4,261

    17 hours ago
    Trump Media Cuts Another 2,628 Btc; Wallet Drops To 4,261 Btc

    Trump Media Cuts Another 2,628 BTC; Wallet Drops to 4,261 BTC

    18 hours ago

    Search Crypto News

    Featured Crypto News

    Win 3 Free Ga Passes To Bitcoin Asia 2026 In Hong Kong With Cryptobreaking

    Win 3 Free GA Passes to Bitcoin Asia 2026 in Hong Kong With CryptoBreaking

    24 July 2026

    Latest News

    • Coldcard’s 5-Year Flaw Shows Hardware Wallet Testing Gaps, Kraken Chief
    • Coldcard exploit drives Bitcoin outflows as “hodlers” consolidate—Aug 2 digest
    • Strategy Maintains 12% STRC Preferred Dividend Despite Below-Par Price
    • Strategy Maintains 12% Preferred STRC Dividend Despite Discount
    • Coldcard Hack Fallout Widens as Bitcoin Losses Hit $88.6M
    • Trump Media Moves 2,628 BTC to Crypto.com, Wallet Drops to 4,261
    • Trump Media Cuts Another 2,628 BTC; Wallet Drops to 4,261 BTC
    • Coldcard Hack Triggers Largest Sub-1 BTC Shift Since FTX, CryptoQuant
    • Crypto Legal Roundup: FTX Case Advances as Polymarket Dispute and $35K Penalty Emerge
    • Crypto Court Battle Highlights: Key On-Chain Legal Updates This Week

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    eToro Crypto 300x300
    Bitpanda

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    eToro Crypto 300x300
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!